CVE-2019-6974
- EPSS 7.22%
- Published 15.02.2019 15:29:00
- Last modified 21.11.2024 04:47:20
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
CVE-2019-6589
- EPSS 0.29%
- Published 14.02.2019 00:29:00
- Last modified 21.11.2024 04:46:45
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Management User Interface) also known as the BIG-IP c...
CVE-2018-15333
- EPSS 0.13%
- Published 28.12.2018 15:29:00
- Last modified 21.11.2024 03:50:35
On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access and download previously generated and available snapshot files on the BIG-IP configuration utility such...
CVE-2018-15329
- EPSS 0.28%
- Published 20.12.2018 20:29:00
- Last modified 21.11.2024 03:50:34
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, r...
CVE-2018-15330
- EPSS 0.61%
- Published 20.12.2018 20:29:00
- Last modified 21.11.2024 03:50:34
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a payload, the BIG-IP system will experience a fatal error and may cause the Traffic Management Microkerne...
CVE-2018-15328
- EPSS 2.18%
- Published 12.12.2018 14:29:00
- Last modified 21.11.2024 03:50:34
On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Se...
CVE-2018-15317
- EPSS 0.82%
- Published 31.10.2018 14:29:00
- Last modified 21.11.2024 03:50:32
In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.2.1-11.6.3.2, an attacker sending specially crafted SSL records to a SSL Virtual Server will cause corruption in the SSL data structures leading to intermittent decrypt BAD_RECORD_MA...
CVE-2018-15318
- EPSS 0.61%
- Published 31.10.2018 14:29:00
- Last modified 21.11.2024 03:50:33
In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart ...
CVE-2018-15319
- EPSS 0.59%
- Published 31.10.2018 14:29:00
- Last modified 21.11.2024 03:50:33
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with the non-default "normalize URI" configuration options used in iRul...
CVE-2018-15320
- EPSS 0.68%
- Published 31.10.2018 14:29:00
- Last modified 21.11.2024 03:50:33
On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for the BIG-IP system. The configuration which exposes this condition is the BIG-IP self IP address which is part of a VLAN group and ...