Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2011-4963EPSS 6%
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files vi…
Nginx
1.2.1+
HIGH 7.8
CVE-2012-1493EPSS 63%
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before …
Big Ip Application Security Manager
Patch available
MEDIUM 6.8
CVE-2012-2089EPSS 10%
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 direc…
Nginx
after 1.1.18
MEDIUM 5.0
CVE-2012-1180EPSS 10%
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process m…
Nginx
1.0.14 / 1.1.17+
HIGH 7.5
CVE-2012-1777
SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL comma…
Firepass
No fix yet
HIGH 7.2
CVE-2012-2053
The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as…
Firepass
No fix yet
MEDIUM 6.8
CVE-2011-4315EPSS 6%
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial …
Nginx
1.0.10+
MEDIUM 5.0
CVE-2010-2263EPSS 72%
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrar…
Nginx
0.7.66+
MEDIUM 5.0
CVE-2010-2266EPSS 22%
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corru…
Nginx
0.7.67+
MEDIUM 6.8
CVE-2009-4487EPSS 30%
nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or…
Nginx
Patch available
HIGH 7.8
CVE-2009-4420
Buffer overflow in the bd daemon in F5 Networks BIG-IP Application Security Manager (ASM) 9.4.4 through 9.4.7 and 10.0.0 through 10.0.1, and Protocol…
Big Ip Protocol Security Module
Mitigation only
MEDIUM 5.0
CVE-2009-3896EPSS 10%
src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x befo…
Nginx
Patch available
HIGH 7.5
CVE-2009-2629EPSS 75%
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows…
Nginx
0.5.38 / 0.6.39+
MEDIUM 6.8
CVE-2008-7032
Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hi…
Big Ip
No fix yet
HIGH 9.0
CVE-2008-6474
The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unsp…
Tmos
Mitigation only
HIGH 7.8
CVE-2008-3149
The SNMP daemon in the F5 FirePass 1200 6.0.2 hotfix 3 allows remote attackers to cause a denial of service (daemon crash) by walking the hrSWInstall…
Firepass 1200
Mitigation only
HIGH 7.5
CVE-2007-3097
my.activation.php3 in F5 FirePass 4100 SSL VPN allows remote attackers to execute arbitrary shell commands via shell metacharacters in the username p…
Firepass 4100
Patch available
HIGH 7.5
CVE-2007-0187
F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (…
Firepass
Mitigation only
MEDIUM 6.8
CVE-2007-0186
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the …
Firepass 4100
Mitigation only
MEDIUM 6.5
CVE-2007-0188
F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP …
Firepass
Mitigation only
MEDIUM 5.0
CVE-2007-0195
my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than fo…
Firepass
Mitigation only
MEDIUM 5.1
CVE-2006-5416
Cross-site scripting (XSS) vulnerability in my.acctab.php3 in F5 Networks FirePass 1000 SSL VPN 5.5, and possibly earlier, allows remote attackers to…
Firepass 1000
Patch available
HIGH 7.5
CVE-2005-2245
Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors…
Tmos
Patch available
HIGH 7.5
CVE-2004-1307EPSS 6%
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF …
Icontrol Service Manager
Patch available
MEDIUM 5.0
CVE-1999-1550EPSS 9%
bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.
Tmos
Mitigation only