CVE-2013-0150
published 2013-08-09CVE-2013-0150: Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through…
PriorityP356critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.32%
92.8th percentile
Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other products "when APM is provisioned," allows remote attackers to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_access_policy_manager | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_analytics | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_application_security_manager | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_application_security_manager | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_edge_gateway | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_edge_gateway | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_global_traffic_manager | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_global_traffic_manager | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_link_controller | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_link_controller | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_local_traffic_manager | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_local_traffic_manager | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_policy_enforcement_manager | — | — |
| f5 | big-ip_protocol_security_module | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_protocol_security_module | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_wan_optimization_manager | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_wan_optimization_manager | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_webaccelerator | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_webaccelerator | 11.0.0 – 11.3.0 | — |
| f5 | firepass | — | — |
| f5 | firepass | 6.0.0 – 6.1.0 | — |
| qemu | qemu | >= 0 < 2.0.0~rc1+dfsg-0ubuntu3.1 | 2.0.0~rc1+dfsg-0ubuntu3.1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wxch-2vvj-p58q: Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10
ghsa_unreviewed·2022-05-05
CVE-2013-0150 [HIGH] CWE-22 GHSA-wxch-2vvj-p58q: Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10
Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other products "when APM is provisioned," allows remote attackers to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-04-28·CVSS 4.9
CVE-2013-4544 qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Michael S. Tsirkin discovered that QEMU incorrectly handled vmxnet3
devices. A local guest could possibly use this issue to cause a denial of
service, or possibly execute arbitrary code on the host. This issue only
applied to Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2013-4544)
Michael S. Tsirkin discovered that QEMU incorrectly handled virtio-net
MAC addresses. A local guest could possibly use this issue to cause a
denial of service, or possibly execute arbitrary code on the host.
(CVE-2014-0150)
Benoît Canet discovered that QEMU incorrectly handled SMART self-tests. A
local guest could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code on the host. (CVE-2014-2894)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/53477http://support.f5.com/kb/en-us/solutions/public/14000/400/sol14468.htmlhttps://nealpoole.com/blog/2013/07/code-execution-via-f5-networks-java-applet/http://secunia.com/advisories/53477http://support.f5.com/kb/en-us/solutions/public/14000/400/sol14468.htmlhttps://nealpoole.com/blog/2013/07/code-execution-via-f5-networks-java-applet/
2013-08-09
Published