|
208361
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27719
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208362
|
7.5 |
HIGH
Network
|
f5
|
big-ip_domain_name_system
|
On BIG-IP DNS 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, undisclosed series of DNS requests may cause TMM to restart and generate a core file.
|
NVD-CWE-noinfo
|
CVE-2020-27717
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208363
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager
|
On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM virtual server processes traffic of an undisclosed nature, the Traffic Management …
|
NVD-CWE-noinfo
|
CVE-2020-27716
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208364
|
7.5 |
HIGH
Network
|
f5
|
big-ip_advanced_firewall_manager
|
On the BIG-IP AFM version 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when a Protocol Inspection Profile is attached to a FastL4 virtual server with the protocol field configured to either O…
|
NVD-CWE-noinfo
|
CVE-2020-27714
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208365
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface via port 443 can cause high (~100%) CPU utilization by the httpd daemon.
|
NVD-CWE-noinfo
|
CVE-2020-27715
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208366
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_global_traffic_manager big-ip_link_controller big-ip_domain_name_system
|
In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be liste…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-27725
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208367
|
6.5 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenti…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-27724
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208368
|
7.5 |
HIGH
Network
|
f5
|
big-ip_global_traffic_manager big-ip_domain_name_system
|
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.1, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, in a BIG-IP DNS / BIG-IP LTM GSLB deployment, under certain circumstances, the BIG-IP…
|
NVD-CWE-noinfo
|
CVE-2020-27721
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208369
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall
|
When a BIG-IP ASM or Advanced WAF system running version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, or 11.6.1-11.6.5.2 processes requests with JSON payload, an…
|
NVD-CWE-noinfo
|
CVE-2020-27718
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208370
|
8.8 |
HIGH
Network
|
projectworlds
|
online_matrimonial_project
|
Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-27397
|
2024-11-21 14:21 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|