CVE-2024-28883
- EPSS 0.05%
- Veröffentlicht 08.05.2024 15:15:09
- Zuletzt bearbeitet 06.08.2025 15:56:39
An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical...
CVE-2024-27202
- EPSS 0.48%
- Veröffentlicht 08.05.2024 15:15:08
- Zuletzt bearbeitet 21.10.2025 19:28:16
A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reac...
CVE-2024-25560
- EPSS 0.36%
- Veröffentlicht 08.05.2024 15:15:08
- Zuletzt bearbeitet 21.10.2025 11:40:17
When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2014-9342
- EPSS 0.3%
- Veröffentlicht 08.12.2014 11:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in F5 BIG-IP 11.3.0 allows remote attackers to inject arbitrary web script or HTML by accessing a crafted URL during automatic polic...
CVE-2007-6258
- EPSS 39.39%
- Veröffentlicht 19.02.2008 00:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.