Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2015-8240
The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and BIG-IP PEM before 11.4.1 HF10, 11…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 5.3
CVE-2016-0747EPSS 8%
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial …
Nginx
1.8.1 / 1.9.10+
CRITICAL 9.8
CVE-2016-0746EPSS 9%
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of servi…
Nginx
1.9.10 / 13.0+
HIGH 7.5
CVE-2016-0742EPSS 82%
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and work…
Nginx
1.8.1 / 1.9.10+
HIGH 7.5
CVE-2015-5516
Memory leak in the last hop kernel module in F5 BIG-IP LTM, GTM, and Link Controller 10.1.x, 10.2.x before 10.2.4 HF13, 11.x before 11.2.1 HF15, 11.3…
Big Iq Application Delivery Controller
Mitigation only
CRITICAL 9.8
CVE-2015-8611
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, and PEM 12.0.0 before HF1 on the 2000, 4000, 5000, 7000, and 10000 platforms do not …
Big Ip Domain Name System
Mitigation only
HIGH 7.4
CVE-2015-7393
dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AAM 11.4.0 through 11.6.0 an…
Big Iq Application Delivery Controller
Mitigation only
CRITICAL 9.8
CVE-2015-8098
F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cause a denial of service or exe…
Big Ip Access Policy Manager
Mitigation only
HIGH 9.0
CVE-2015-3628EPSS 68%
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP A…
Big Iq Security
No fix yet
HIGH 9.0
CVE-2015-7394
The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP A…
Big Iq Device
Mitigation only
MEDIUM 6.1
CVE-2015-6546
The vCMP host in F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller, and LTM 11.0.0 before 11.6.0, BIG-IP AAM 11.4.0 before 11.6.0, BIG-IP AFM and P…
Big Ip Application Acceleration Manager
Mitigation only
MEDIUM 5.0
CVE-2015-4638
The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.…
Big Ip Advanced Firewall Manager
Mitigation only
HIGH 7.8
CVE-2015-5058
Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.5.x before 11.5.1 HF10,…
Big Ip Access Policy Manager
Mitigation only
MEDIUM 6.8
CVE-2014-3556EPSS 8%
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not p…
Nginx
1.6.1 / 1.7.4+
MEDIUM 6.2
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role t…
Big Ip Local Traffic Manager
after 10.2.1
MEDIUM 5.5
CVE-2014-6032
Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Controller 11.0 through 11.6.0 a…
Big Ip Protocol Security Module
No fix yet
HIGH 7.5
CVE-2013-7408
F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by gu…
Big Ip Analytics
No fix yet
HIGH 9.3
CVE-2014-2927EPSS 8%
The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and …
Arx
No fix yet
MEDIUM 6.5
CVE-2014-2949
SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL …
Arx Data Manager
Mitigation only
HIGH 7.1
CVE-2014-2928EPSS 39%
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through…
Big Ip Webaccelerator
No fix yet
HIGH 9.0
CVE-2014-3220EPSS 11%
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter i…
Big Iq
No fix yet
HIGH 7.5
CVE-2014-0088EPSS 9%
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers …
Nginx
Patch available
HIGH 7.5
CVE-2014-0133EPSS 9%
Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitra…
Nginx
1.4.7+
HIGH 7.5
CVE-2012-3000
Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, P…
Big Ip Webaccelerator
No fix yet
HIGH 7.5
CVE-2013-4547EPSS 68%
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
Nginx
1.4.4+
HIGH 7.5
CVE-2013-0337
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, whic…
Nginx
after 1.3.13
HIGH 7.8
CVE-2013-6016
The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; An…
Big Ip Global Traffic Manager
Mitigation only
HIGH 9.3
CVE-2013-0150EPSS 6%
Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.…
Big Ip Access Policy Manager
after 11.3.0
MEDIUM 5.8
CVE-2013-2070EPSS 12%
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allow…
Nginx
after 1.4.0
HIGH 7.5
CVE-2013-2028EPSS 87%
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash…
Nginx
after 1.4.0