|
196091
|
7.8 |
HIGH
Local
|
mcafee
|
total_protection
|
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the …
|
CWE-59
Link Following
|
CVE-2021-23872
|
2024-11-21 14:51 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196092
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacker may be able to bypass APM's internal restriction…
|
NVD-CWE-noinfo
|
CVE-2021-23016
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196093
|
7.2 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role …
|
CWE-863
Incorrect Authorization
|
CVE-2021-23015
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196094
|
8.8 |
HIGH
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall
|
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the RE…
|
CWE-862
Missing Authorization
|
CVE-2021-23014
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196095
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_security_manager
|
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and 12.1.x before 12.1.5.3, when the BIG-IP ASM/Advanced WAF system processes WebSocket reque…
|
NVD-CWE-noinfo
|
CVE-2021-23010
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196096
|
8.2 |
HIGH
Local
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow …
|
CWE-78
OS Command
|
CVE-2021-23012
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196097
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configur…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-23009
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196098
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffic Management Microkernel (TMM) may stop responding…
|
NVD-CWE-noinfo
|
CVE-2021-23013
|
2024-11-21 14:51 |
2021-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196099
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, when the BIG-IP system is buffering packet frag…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-23011
|
2024-11-21 14:51 |
2021-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196100
|
9.8 |
CRITICAL
Network
|
f5
|
big-ip_access_policy_manager
|
On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM AD (Active Directory) authentication can be bypas…
|
CWE-287
Improper Authentication
|
CVE-2021-23008
|
2024-11-21 14:51 |
2021-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|