Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-27378 Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker … Big Ip Access Policy Manager 14.1.5.4 / 15.1.8.2+ Fix from $1,6002023-05-03 MEDIUM 5.9 CVE-2023-24461 An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BI… Big Ip Access Policy Manager 7.2.4.1+ Fix from $1,6002023-05-03 MEDIUM 5.3 CVE-2023-24594 When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.   N… Big Ip Access Policy Manager Mitigation only Fix from $1,6002023-05-03 MEDIUM 5.9 CVE-2023-22372 In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS.  Note: S… Big Ip Access Policy Manager 7.2.4.1+ Fix from $1,6002023-05-03 HIGH 7.5 CVE-2023-27727 Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. Njs No fix yet Fix from $1,9502023-04-09 HIGH 7.5 CVE-2023-27728 Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. Njs Patch available Fix from $1,9502023-04-09 HIGH 7.5 CVE-2023-27729 Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. Njs Patch available Fix from $1,9502023-04-09 HIGH 7.5 CVE-2023-27730 Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. Njs Patch available Fix from $1,9502023-04-09 CRITICAL 9.8 CVE-2020-19692 Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_modul… Njs 0.3.4+ Fix from $2,3002023-04-04 CRITICAL 9.8 CVE-2020-19695 Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c funct… Njs 0.3.4+ Fix from $2,3002023-04-04 MEDIUM 5.5 CVE-2023-1550 Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information in… Nginx Agent 2.9.0 / 2.23.3+ Fix from $1,6002023-03-29 HIGH 8.5 CVE-2023-22374EPSS 73% A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially ex… Big Ip Access Policy Manager after 16.1.3 Fix from $1,9502023-02-01 HIGH 7.8 CVE-2023-22358 In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software… Big Ip Access Policy Manager 7.2.3.1 / 17.0.0.2+ Fix from $1,9502023-02-01 HIGH 7.8 CVE-2023-22657 On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may all… F5os A 1.3.0 / 1.5.0+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-22340 On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured… Big Ip Access Policy Manager 14.1.5.3 / 15.1.8+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-22341 On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed … Big Ip Access Policy Manager 14.1.5.3+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-22422 On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Co… Big Ip Access Policy Manager 16.1.3.3 / 17.0.0.2+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-22664 On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and… Big Ip Access Policy Manager 16.1.3.3 / 17.0.0.2+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-22839 On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a … Big Ip Domain Name System 14.1.5.3 / 15.1.7+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-22842 On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configur… Big Ip Access Policy Manager 14.1.5.3 / 15.1.8.1+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-23552 On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP A… Big Ip Advanced Web Application Firewall 14.1.5.3 / 15.1.8+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-23555 On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK begin… Big Ip Access Policy Manager 14.1.5.3 / 15.1.8+ Fix from $1,9502023-02-01 MEDIUM 6.1 CVE-2023-22418 On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirec… Big Ip Access Policy Manager 14.1.5.3 / 15.1.7+ Fix from $1,6002023-02-01 HIGH 7.5 CVE-2023-22281 On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP A… Big Ip Advanced Firewall Manager 14.1.5.3 / 15.1.8+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-22323 In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when O… Big Ip Access Policy Manager 14.1.5.3 / 15.1.8.1+ Fix from $1,9502023-02-01 MEDIUM 6.5 CVE-2023-22283 On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and ad… Big Ip Access Policy Manager 7.2.3.1 / 17.0.0.2+ Fix from $1,6002023-02-01 MEDIUM 5.9 CVE-2023-22302 In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual serve… Big Ip Access Policy Manager 16.1.3.3 / 17.0.0.2+ Fix from $1,6002023-02-01 HIGH 8.8 CVE-2022-41622EPSS 88% In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions wh… Big Iq Centralized Management after 16.1.3 Fix from $1,9502022-12-07 HIGH 8.7 CVE-2022-41800EPSS 66% In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode… Big Ip Access Policy Manager after 17.0.0 Fix from $1,9502022-12-07 CRITICAL 9.8 CVE-2022-43286 Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at nj… Njs Patch available Fix from $2,3002022-10-28