Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
469 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.4% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+6 | 7/3/2017 | 17/6/2026 | In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the non-default "Normalize URI" configuration options used in iRules and/or BIG-IP… | |
| Modificada | Media (5.3) | 0.33% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+7 | 20/2/2017 | 17/6/2026 | F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files. | |
| Modificada | Alta (7.5) | 2.0% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+6 | 31/1/2017 | 17/6/2026 | An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS). | |
| Modificada | Media (5.9) | 1.9% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+6 | 10/1/2017 | 17/6/2026 | Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffic Management Microkernel (TMM) to restart. | |
| Modificada | Media (5.9) | 1.8% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+6 | 3/1/2017 | 17/6/2026 | Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traffic. | |
| Modificada | Alta (7.5) | 1.6% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip WebacceleratorF5 Big-ip Application Acceleration ManagerF5 Big-ip Global Traffic Manager+10 | 7/9/2016 | 17/6/2026 | The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP Analytics 11.2.1,… | |
| Modificada | Crítica (9.8) | 3.5% | — | F5 Big-ip Link ControllerF5 Big-ip Policy Enforcement ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Global Traffic Manager+18 | 7/9/2016 | 17/6/2026 | F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before… | |
| Modificada | Alta (7.5) | 3.0% | — | F5 Big-ip Edge GatewayF5 Big-ip Protocol Security ModuleF5 Big-ip AnalyticsF5 Big-ip Application Security Manager+9 | 26/8/2016 | 17/6/2026 | Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configured with a TCP profile, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traffic. | |
| Modificada | Media (4.9) | 1.5% | — | F5 Big-ip WebacceleratorF5 Big-ip Link ControllerF5 Big-ip Access Policy ManagerF5 Big-ip Application Security Manager+10 | 26/8/2016 | 17/6/2026 | The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4 HF2, 1.6.x before 11.6.1, and 12.0.0 before HF1 allows remote administrators to read Access Policy Manager (APM) access logs via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | F5 Big-ip Application Acceleration ManagerF5 Big-ip WebacceleratorF5 Big-ip AnalyticsF5 Big-ip Domain Name System+11 | 19/8/2016 | 17/6/2026 | The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before… | |
| Modificada | Alta (8.8) | 3.4% | — | F5 Big-ip WAN Optimization ManagerF5 Big-ip Protocol Security ModuleF5 Big-ip Application Acceleration ManagerF5 Big-ip Edge Gateway+10 | 30/6/2016 | 17/6/2026 | F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Resource Administration role and gain privilege via a crafted external Extended Application Verification (EAV) monitor script. | |
| Modificada | Media (4.9) | 1.2% | — | F5 Big-iq Application Delivery ControllerF5 Big-iq Cloud AND OrchestrationF5 Big-ip Application Acceleration ManagerF5 Big-ip Access Policy Manager+12 | 24/6/2016 | 17/6/2026 | The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x before 11.6.1; BIG-IQ Cloud and Security 4.0.0 through 4.5.0; BIG-IQ… | |
| Modificada | Media (5.9) | 2.0% | — | F5 Big-ip Access Policy ManagerF5 Big-ip WAN Optimization ManagerF5 Big-ip Application Security ManagerF5 Big-ip Link Controller+17 | 13/5/2016 | 17/6/2026 | F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP DNS 12.x before 12.0.0 HF1;… | |
| Modificada | Alta (7.4) | 0.79% | — | F5 Big-iq SecurityF5 Big-ip WebacceleratorF5 Big-ip Application Security ManagerF5 Big-ip Access Policy Manager+14 | 13/4/2016 | 17/6/2026 | F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build… | |
| Modificada | Alta (8.1) | 91% | 💥 Exploit | Debian LinuxCanonical Ubuntu LinuxHP Helion OpenstackHP Server Migration Pack+26 | 18/2/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the… | |
| Modificada | Crítica (9.8) | 3.2% | — | F5 Big-ip Domain Name SystemF5 Big-ip Application Acceleration ManagerF5 Big-ip Link ControllerF5 Big-ip Policy Enforcement Manager+5 | 12/1/2016 | 17/6/2026 | BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, and PEM 12.0.0 before HF1 on the 2000, 4000, 5000, 7000, and 10000 platforms do not properly sync passwords with the Always-On Management (AOM) subsystem, which might allow remote attackers to obtain login access to AOM via an (1) expired or (2) default… | |
| Modificada | Alta (7.4) | 0.34% | — | F5 Big-iq Application Delivery ControllerF5 Big-ip Application Security ManagerF5 Big-iq SecurityF5 Big-ip WAN Optimization Manager+16 | 12/1/2016 | 17/6/2026 | dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AAM 11.4.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AFM and PEM 11.3.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP DNS 12.0.0 before 12.0.0 HF1, BIG-IP Edge Gateway,… | |
| Modificada | Alta (7.8) | 9.7% | — | Ipsec-toolsCanonical Ubuntu LinuxFedoraproject FedoraF5 Big-ip Application Acceleration Manager+21 | 29/5/2015 | 17/6/2026 | racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. | |
| Modificada | Baja (2.3) | 0.65% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxSuse Linux Enterprise Desktop+22 | 23/6/2014 | 17/6/2026 | The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator. |