Page 14 of 81 results (0.009 seconds)

CVSS: 6.1EPSS: 0%CPEs: 101EXPL: 0

The vCMP host in F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller, and LTM 11.0.0 before 11.6.0, BIG-IP AAM 11.4.0 before 11.6.0, BIG-IP AFM and PEM 11.3.0 before 11.6.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.0.0 through 11.3.0, BIG-IP PSM 11.0.0 through 11.4.1 allows remote attackers to cause a denial of service via "malicious traffic." El host vCMP en F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller y LTM 11.0.0 en versiones anteriores a 11.6.0, BIG-IP AAM 11.4.0 en versiones anteriores a 11.6.0, BIG-IP AFM y PEM 11.3.0 en versiones anteriores a 11.6.0, BIG-IP Edge Gateway, WebAccelerator y WOM 11.0.0 hasta la versión 11.3.0, BIG-IP PSM 11.0.0 hasta la versión 11.4.1 permite a atacantes remotos provocar una denegación de servicio a través de 'tráfico malicioso'. • http://www.securitytracker.com/id/1033952 https://support.f5.com/kb/en-us/solutions/public/17000/300/sol17386.html • CWE-20: Improper Input Validation •

CVSS: 5.0EPSS: 0%CPEs: 57EXPL: 0

The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 through 11.3.0, and BIG-IP PSM 11.2.1 through 11.4.1 allows remote attackers to cause a denial of service (Traffic Management Microkernel restart) via a fragmented packet. Vulnerabilidad en el servidor virtual FastL4 en F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller y PEM 11.3.0 hasta la versión 11.5.2 y 11.6.0 hasta la versión 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator y WOM 11.2.1 hasta la versión 11.3.0 y BIG-IP PSM 11.2.1 hasta la versión 11.4.1, permite a atacantes remotos causar una denegación de servicio (reinicio del Traffic Management Microkernel) a través de un paquete fragmentado. • http://www.securitytracker.com/id/1033578 https://support.f5.com/kb/en-us/solutions/public/17000/100/sol17155.html • CWE-20: Improper Input Validation •

CVSS: 4.0EPSS: 3%CPEs: 16EXPL: 1

Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors. Vulnerabilidad de salto de directorio en la utilidad de configuración en F5 BIG-IP en versiones anteriores a 12.0.0 y Enterprise Manager 3.0.0 hasta la versión 3.1.1, permite a usuarios remotos autenticados acceder a archivos arbitrarios en la raíz web a través de vectores no especificados. F5 BigIP version 10.2.4 Build 595.0 Hotfix HF3 suffers from a path traversal vulnerability. • https://www.exploit-db.com/exploits/38448 http://packetstormsecurity.com/files/133931/F5-BigIP-10.2.4-Build-595.0-HF3-Path-Traversal.html http://www.securitytracker.com/id/1033532 http://www.securitytracker.com/id/1033533 https://support.f5.com/kb/en-us/solutions/public/17000/200/sol17253.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.8EPSS: 1%CPEs: 45EXPL: 4

racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. racoon/gssapi.c en IPsec-Tools 0.8.2 permite a atacantes remotos causar una denegación de servicios (referencia a puntero nulo y caída de demonio IKE) a través de una serie de solicitudes UDP manipuladas. • http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159482.html http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159549.html http://packetstormsecurity.com/files/131992/IPsec-Tools-0.8.2-Denial-Of-Service.html http://seclists.org/fulldisclosure/2015/May/81 http://seclists.org/fulldisclosure/2015/May/83 http://www.debian.org/security/2015/dsa-3272 http://www.openwall.com/lists/oss-security/2015/05/20/1 http://www.openwall.com/lists/oss-security/20 • CWE-476: NULL Pointer Dereference •

CVSS: 4.3EPSS: 0%CPEs: 43EXPL: 0

The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM 10.0.0 through 11.6.0 and PEM 11.3.0 through 11.6.0 does not properly validate server SSL certificates, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate. La funcionalidad de la actualización automática de firmas en (1) la característica Phone Home en F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, y Link Controller 11.5.0 hasta 11.6.0, ASM 10.0.0 hasta 11.6.0, y PEM 11.3.0 hasta 11.6.0 y (2) la característica Call Home en ASM 10.0.0 hasta 11.6.0 y PEM 11.3.0 hasta 11.6.0 no valida correctamente los certificados SSL de servidores, lo que permite a atacantes remotos realizar ataques man-in-the-middle a través de un certificado manipulado. • http://www.securitytracker.com/id/1032305 https://support.f5.com/kb/en-us/solutions/public/16000/000/sol16090.html •