Записи F5
1 039 опубликованных записей вендора f5.
Профиль для исследователя
- Попали в KEV
- 14 · 1,3 %
- С эксплойтом
- 22 · 2,1 %
- Pre-auth RCE
- 32
- С записью об исправлении
- 19,9 %
- Медиана: публикация → KEV
- 190 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation79
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')75
- CWE-400 Uncontrolled Resource Consumption57
- CWE-476 NULL Pointer Dereference34
- CWE-125 Out-of-bounds Read31
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 039 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2020-5902Готовый эксплойт | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Intef5 · big-ip access policy manager · CWE-22 | Критическая9,8 | KEV | 100,0 % | 1 июл. 2020 г. |
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2022-1388Готовый эксплойт | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior f5 · big-ip access policy manager · CWE-306 | Критическая9,8 | KEV | 100,0 % | 5 мая 2022 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2021-22986Готовый эксплойт | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 f5 · big-ip access policy manager · CWE-918 | Критическая9,8 | KEV | 99,9 % | 31 мар. 2021 г. |
98Срочно | CVE-2023-46747Готовый эксплойт | BIG-IP Configuration utility unauthenticated remote code execution vulnerabilityf5 · big-ip access policy manager · CWE-288 | Критическая9,8 | KEV | 96,5 % | 26 окт. 2023 г. |
96Срочно | CVE-2021-40438Готовый эксплойт | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Критическая9,0 | KEV | 100,0 % | 16 сент. 2021 г. |
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
87Срочно | CVE-2021-22991Готовый эксплойт | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,f5 · big-ip access policy manager · CWE-119 | Критическая9,8 | KEV | 61,1 % | 31 мар. 2021 г. |
68На этой неделе | CVE-2025-53521Готовый эксплойт | BigIP APM Vulnerabilityf5 · big-ip access policy manager · CWE-121 | Критическая9,3 | KEV | 2,3 % | 15 окт. 2025 г. |
68На этой неделе | CVE-2026-94127Готовый эксплойт | BIG-IP APM OAuth vulnerabilityf5 · big-ip access policy manager · CWE-122 | Критическая9,3 | KEV | 2,2 % | 22 сент. 2026 г. |
66На этой неделе | CVE-2023-46748Готовый эксплойт | BIG-IP Configuration utility authenticated SQL injection vulnerabilityf5 · big-ip access policy manager · CWE-89 | Высокая8,8 | KEV | 4,5 % | 26 окт. 2023 г. |
65На этой неделе | CVE-2009-3555Proof of concept | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Критическая9,8 | — | 87,3 % | 9 нояб. 2009 г. |
65На этой неделе | CVE-2018-14634Готовый эксплойт | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.linux · linux kernel · CWE-190 | Высокая7,8 | KEV | 14,7 % | 25 сент. 2018 г. |
63На этой неделе | CVE-2022-41622Готовый эксплойт | iControl SOAP vulnerabilityf5 · big-iq centralized management · CWE-352 | Высокая8,8 | — | 92,3 % | 7 дек. 2022 г. |
61На этой неделе | CVE-2021-22992Эксплойта нет | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, andf5 · big-ip access policy manager · CWE-120 | Критическая9,8 | — | 72,7 % | 31 мар. 2021 г. |
60На этой неделе | CVE-2019-11477Proof of concept | Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segslinux · linux kernel · CWE-190 | Высокая7,5 | — | 98,7 % | 18 июн. 2019 г. |
59В плане | CVE-2015-7547Proof of concept | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc gnu · glibc · CWE-119 | Высокая8,1 | — | 91,0 % | 18 февр. 2016 г. |
59В плане | CVE-2014-0196Готовый эксплойт | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO linux · linux kernel · CWE-362 | Средняя5,5 | KEV | 22,5 % | 7 мая 2014 г. |
58В плане | CVE-2019-11478Эксплойта нет | SACK can cause extensive memory use via fragmented resend queuelinux · linux kernel · CWE-770 | Высокая7,5 | — | 94,7 % | 18 июн. 2019 г. |
57В плане | CVE-2019-11479Эксплойта нет | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.linux · linux kernel · CWE-405 | Высокая7,5 | — | 91,7 % | 18 июн. 2019 г. |
57В плане | CVE-2022-41800Готовый эксплойт | Appliance mode iControl REST vulnerabilityf5 · big-ip access policy manager · CWE-77 | Высокая8,7 | — | 76,9 % | 7 дек. 2022 г. |
57В плане | CVE-2015-3628Готовый эксплойт | The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,f5 · big-iq security · CWE-264 | Критическая9,0 | — | 69,3 % | 7 дек. 2015 г. |
56В плане | CVE-2013-2028Готовый эксплойт | The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of servif5 · nginx · CWE-787 | Высокая7,5 | — | 87,5 % | 19 июл. 2013 г. |
56В плане | CVE-2019-9515Эксплойта нет | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 87,4 % | 13 авг. 2019 г. |
- CVE-2020-590299Срочно
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %f5 · big-ip access policy manager1 июл. 2020 г.
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2022-138899Срочно
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %f5 · big-ip access policy manager5 мая 2022 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2021-2298699Срочно
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %f5 · big-ip access policy manager31 мар. 2021 г.
- CVE-2023-4674798Срочно
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %f5 · big-ip access policy manager26 окт. 2023 г.
- CVE-2021-4043896Срочно
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %resf · rocky linux16 сент. 2021 г.
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2021-2299187Срочно
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 61 %f5 · big-ip access policy manager31 мар. 2021 г.
- CVE-2025-5352168На этой неделе
BigIP APM Vulnerability
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 2 %f5 · big-ip access policy manager15 окт. 2025 г.
- CVE-2026-9412768На этой неделе
BIG-IP APM OAuth vulnerability
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 2 %f5 · big-ip access policy manager22 сент. 2026 г.
- CVE-2023-4674866На этой неделе
BIG-IP Configuration utility authenticated SQL injection vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 4 %f5 · big-ip access policy manager26 окт. 2023 г.
- CVE-2009-355565На этой неделе
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
КритическаяCVSS 9,8Proof of conceptEPSS 87 %apache · http server9 нояб. 2009 г.
- CVE-2018-1463465На этой неделе
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 15 %linux · linux kernel25 сент. 2018 г.
- CVE-2022-4162263На этой неделе
iControl SOAP vulnerability
ВысокаяCVSS 8,8Готовый эксплойтEPSS 92 %f5 · big-iq centralized management7 дек. 2022 г.
- CVE-2021-2299261На этой неделе
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and
КритическаяCVSS 9,8Эксплойта нетEPSS 73 %f5 · big-ip access policy manager31 мар. 2021 г.
- CVE-2019-1147760На этой неделе
Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
ВысокаяCVSS 7,5Proof of conceptEPSS 99 %linux · linux kernel18 июн. 2019 г.
- CVE-2015-754759В плане
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc
ВысокаяCVSS 8,1Proof of conceptEPSS 91 %gnu · glibc18 февр. 2016 г.
- CVE-2014-019659В плане
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 22 %linux · linux kernel7 мая 2014 г.
- CVE-2019-1147858В плане
SACK can cause extensive memory use via fragmented resend queue
ВысокаяCVSS 7,5Эксплойта нетEPSS 95 %linux · linux kernel18 июн. 2019 г.
- CVE-2019-1147957В плане
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.
ВысокаяCVSS 7,5Эксплойта нетEPSS 92 %linux · linux kernel18 июн. 2019 г.
- CVE-2022-4180057В плане
Appliance mode iControl REST vulnerability
ВысокаяCVSS 8,7Готовый эксплойтEPSS 77 %f5 · big-ip access policy manager7 дек. 2022 г.
- CVE-2015-362857В плане
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,
КритическаяCVSS 9,0Готовый эксплойтEPSS 69 %f5 · big-iq security7 дек. 2015 г.
- CVE-2013-202856В плане
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of servi
ВысокаяCVSS 7,5Готовый эксплойтEPSS 87 %f5 · nginx19 июл. 2013 г.
- CVE-2019-951556В плане
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 87 %apple · swiftnio13 авг. 2019 г.