CVE-2014-6031
- EPSS 0.47%
- Veröffentlicht 08.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Buffer overflow in the mcpq daemon in F5 BIG-IP systems 10.x before 10.2.4 HF12, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x before 11.4.1 HF9, 11.5.x before 11.5.2 HF1, and 11.6.0 before HF4, and Enterprise Manager 2.1.0 through 2.3.0 and 3.x before 3.1...
CVE-2016-7476
- EPSS 1.2%
- Veröffentlicht 11.05.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and 11.3.0 before 11.4.1 HF10 may suffer from a memory leak while handling ...
CVE-2016-9250
- EPSS 0.61%
- Veröffentlicht 10.05.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.
CVE-2017-6137
- EPSS 0.7%
- Veröffentlicht 09.05.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, and WebSafe 11.6.1 HF1, 12.0.0 HF3, 12.0.0 HF4, and 12.1.0 through 12.1.2, undisclosed traffic patterns received while software SYN co...
CVE-2017-6128
- EPSS 0.93%
- Veröffentlicht 01.05.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.
CVE-2016-9252
- EPSS 1.2%
- Veröffentlicht 27.03.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle minimum path MTU options for IPv6, which allows remote attackers to cause a denial-of-service (DoS) thro...
CVE-2016-7474
- EPSS 0.11%
- Veröffentlicht 27.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporarily obtain normally unrecoverable information.
CVE-2016-7468
- EPSS 0.92%
- Veröffentlicht 23.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An unauthenticated remote attacker may be able to disrupt services on F5 BIG-IP 11.4.1 - 11.5.4 devices with maliciously crafted network traffic. This vulnerability affects virtual servers associated with TCP profiles when the BIG-IP system's tm.tcpp...
CVE-2016-6249
- EPSS 0.06%
- Veröffentlicht 20.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by r...
CVE-2016-9244
- EPSS 73.65%
- Veröffentlicht 09.02.2017 15:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL...