cbcvebase.

F5 Big-Ip Domain Name System vulnerabilities

463 known vulnerabilities affecting f5/big-ip_domain_name_system.

Total CVEs
463
CISA KEV
8
actively exploited
Public exploits
11
Exploited in wild
11
Severity breakdown
CRITICAL32HIGH264MEDIUM163LOW4

Vulnerabilities

Page 24 of 24
CVE-2019-6679P4LOWCVSS 3.3≥ 11.5.9, ≤ 11.5.10≥ 11.6.4, < 11.6.5.1+5 more2019-12-23
CVE-2019-6679 [LOW] CWE-59 CVE-2019-6679: On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12 On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.blacklist are not properly enforced for paths that are symlinks. This allows authenticated users with SCP access to overwrite certain configuration files that
nvd
CVE-2019-11109P4MEDIUMCVSS 4.4≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-12-18
CVE-2019-11109 [MEDIUM] CVE-2019-11109: Logic issue in the subsystem for Intel(R) SPS before versions SPS_E5_04.01.04.275.0, SPS_SoC-X_04.00 Logic issue in the subsystem for Intel(R) SPS before versions SPS_E5_04.01.04.275.0, SPS_SoC-X_04.00.04.100.0 and SPS_SoC-A_04.00.04.191.0 may allow a privileged user to potentially enable denial of service via local access.
nvd
CVE-2014-4027P4LOWCVSS 2.3v12.0.02014-06-23
CVE-2014-4027 [LOW] CWE-200 CVE-2014-4027: The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.1 The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.
nvd
F5 Big-Ip Domain Name System vulnerabilities | cvebase