F5 / Big-IP Wan Optimization Manager
38 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2013-3587 | BREACH attack against HTTP compression | MEDIUM | 5.9 | Feb 21, 2020 |
| CVE-2014-5209 | ntp: Information Disclosure vulnerability via GET_RESTRICT control message | MEDIUM | 5.3 | Jan 8, 2020 |
| CVE-2014-4024 | SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 befo… | MEDIUM | 5.9 | Mar 19, 2018 |
| CVE-2016-7469 | A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge… | MEDIUM | 5.4 | Jun 9, 2017 |
| CVE-2014-6031 | Buffer overflow in the mcpq daemon in F5 BIG-IP systems 10.x before 10.2.4 HF12, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x before 11.4.1 HF9, 11.5.x before 11.5.… | MEDIUM | 4.9 | Jun 8, 2017 |
| CVE-2016-6876 | The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before… | HIGH | 7.5 | Sep 7, 2016 |
| CVE-2016-5022 | F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x… | CRITICAL | 9.8 | Sep 7, 2016 |
| CVE-2016-5023 | Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configu… | HIGH | 7.5 | Aug 26, 2016 |
| CVE-2016-1497 | The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4 HF2, 1.6.x be… | MEDIUM | 4.9 | Aug 26, 2016 |
| CVE-2016-5736 | The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 1… | HIGH | 7.5 | Aug 19, 2016 |
| CVE-2015-8022 | The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x be… | HIGH | 7.5 | Aug 19, 2016 |
| CVE-2016-5020 | F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Resource Administration role and gain privi… | HIGH | 8.8 | Jun 30, 2016 |
| CVE-2015-8099 | F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x befor… | MEDIUM | 5.9 | May 13, 2016 |
| CVE-2016-2084 | F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11… | HIGH | 7.4 | Apr 13, 2016 |
| CVE-2015-8021 | Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 1… | MEDIUM | 4.3 | Apr 12, 2016 |
| CVE-2015-5516 | Memory leak in the last hop kernel module in F5 BIG-IP LTM, GTM, and Link Controller 10.1.x, 10.2.x before 10.2.4 HF13, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x… | HIGH | 7.5 | Jan 20, 2016 |
| CVE-2015-7393 | dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AAM 11.4.0 through 11.6.0 and 12.0.0 b… | HIGH | 7.4 | Jan 12, 2016 |
| CVE-2015-3628 | The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0… | HIGH | 9.0 | Dec 7, 2015 |
| CVE-2015-7394 | The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11… | HIGH | 9.0 | Nov 6, 2015 |
| CVE-2015-6546 | The vCMP host in F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller, and LTM 11.0.0 before 11.6.0, BIG-IP AAM 11.4.0 before 11.6.0, BIG-IP AFM and PEM 11.3.0… | MEDIUM | 6.1 | Nov 6, 2015 |
| CVE-2015-4040 | Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticate… | MEDIUM | 4.0 | Sep 17, 2015 |
| CVE-2015-4047 | ipsec-tools: NULL pointer dereference in racoon/gssapi.c | HIGH | 7.8 | May 29, 2015 |
| CVE-2014-8730 | TLS: incorrect check of padding bytes when using CBC cipher suites | MEDIUM | 4.3 | Dec 10, 2014 |
| CVE-2014-6032 | Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Controller 11.0 through 11.6.0 and 10.0.0… | MEDIUM | 5.5 | Nov 1, 2014 |
| CVE-2014-4023 | Cross-site scripting (XSS) vulnerability in tmui/dashboard/echo.jsp in the Configuration utility in F5 BIG-IP LTM, APM, ASM, GTM, and Link Controller 11.0.0 be… | MEDIUM | 4.3 | Oct 28, 2014 |
Showing 1 to 25 of 38 CVEs