CVE-2018-5504
- EPSS 3.09%
- Published 22.03.2018 18:29:00
- Last modified 21.11.2024 04:08:56
In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG...
CVE-2014-4024
- EPSS 0.6%
- Published 19.03.2018 21:29:00
- Last modified 21.11.2024 02:09:21
SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 before HF5, and 11.5.1 before HF5, when used with third-party Secure Sockets Layer (SSL) accele...
CVE-2018-5500
- EPSS 0.68%
- Published 01.03.2018 16:29:00
- Last modified 21.11.2024 04:08:55
On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) feature enabled will be affecte...
CVE-2018-5501
- EPSS 0.89%
- Published 01.03.2018 16:29:00
- Last modified 21.11.2024 04:08:55
In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excessive buffering due to lack of flow control.
CVE-2017-6151
- EPSS 0.49%
- Published 21.12.2017 17:29:00
- Last modified 20.04.2025 01:37:25
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator and WebSafe software version 13.0.0, undisclosed requests made to BIG-IP virtual servers which make use of the "HTTP/2 profile" may result i...
CVE-2017-6164
- EPSS 2.46%
- Published 21.12.2017 17:29:00
- Last modified 20.04.2025 01:37:25
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator and WebSafe software version 13.0.0, 12.0.0 - 12.1.2, 11.6.0 - 11.6.1 and 11.5.0 - 11.5.4, in some circumstances, Traffic Management Microke...
CVE-2017-6161
- EPSS 2.59%
- Published 27.10.2017 14:29:00
- Last modified 20.04.2025 01:37:25
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator software version 12.0.0 - 12.1.2, 11.6.0 - 11.6.1, 11.4.0 - 11.5.4, 11.2.1, when ConfigSync is configured, attackers on adjacent networks ma...
CVE-2016-7469
- EPSS 0.27%
- Published 09.06.2017 15:29:00
- Last modified 20.04.2025 01:37:25
A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 1...
CVE-2014-6031
- EPSS 0.47%
- Published 08.06.2017 16:29:00
- Last modified 20.04.2025 01:37:25
Buffer overflow in the mcpq daemon in F5 BIG-IP systems 10.x before 10.2.4 HF12, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x before 11.4.1 HF9, 11.5.x before 11.5.2 HF1, and 11.6.0 before HF4, and Enterprise Manager 2.1.0 through 2.3.0 and 3.x before 3.1...
CVE-2016-9250
- EPSS 0.61%
- Published 10.05.2017 14:29:00
- Last modified 20.04.2025 01:37:25
In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.