F5 Traffix Signaling Delivery Controller vulnerabilities

31 known vulnerabilities affecting f5/traffix_signaling_delivery_controller.

Total CVEs
31
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH24MEDIUM5

Vulnerabilities

Page 2 of 2
CVE-2018-20836HIGHCVSS 8.1v5.0.0v5.1.02019-05-07
CVE-2018-20836 [HIGH] CWE-362 CVE-2018-20836: An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timed An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
nvd
CVE-2019-1559MEDIUMCVSS 5.9≥ 5.0.0, ≤ 5.1.0v4.4.02019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2019-9077HIGHCVSS 7.8≥ 5.0.0, ≤ 5.1.02019-02-24
CVE-2019-9077 [HIGH] CWE-787 CVE-2019-9077: An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_spe An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section.
nvd
CVE-2019-9070HIGHCVSS 7.8≥ 5.0.0, ≤ 5.1.02019-02-24
CVE-2019-9070 [HIGH] CWE-125 CVE-2019-9070: An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based bu An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls.
nvd
CVE-2018-1320HIGHCVSS 7.5≥ 5.0.0, ≤ 5.1.02019-01-07
CVE-2018-1320 [HIGH] CWE-295 CVE-2018-1320: Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComple Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.
nvd
CVE-2018-20657HIGHCVSS 7.5≥ 5.0.0, ≤ 5.1.0v4.4.02019-01-02
CVE-2018-20657 [HIGH] CVE-2018-20657: The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
nvd
CVE-2018-20002MEDIUMCVSS 5.5≥ 5.0.0, ≤ 5.1.0v4.4.02018-12-10
CVE-2018-20002 [MEDIUM] CWE-772 CVE-2018-20002: The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (ak The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.
nvd
CVE-2018-14634HIGHCVSS 7.8KEVPoC≥ 5.0.0, ≤ 5.1.0v4.4.02018-09-25
CVE-2018-14634 [HIGH] CWE-190 CVE-2018-14634: An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileg An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
nvd
CVE-2015-5738HIGHCVSS 7.5≥ 3.3.2, ≤ 3.5.1≥ 4.0.0, ≤ 4.4.02016-07-26
CVE-2015-5738 [HIGH] CWE-200 CVE-2015-5738: The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.
nvd
CVE-2014-7169CRITICALCVSS 9.8KEVPoC≥ 4.0.0, ≤ 4.0.5v3.3.2+3 more2014-09-25
CVE-2014-7169 [CRITICAL] CVE-2014-7169: GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definiti GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgi
nvd
CVE-2014-6271CRITICALCVSS 9.8KEVPoC≥ 4.0.0, ≤ 4.0.5v3.3.2+3 more2014-09-24
CVE-2014-6271 [CRITICAL] CWE-78 CVE-2014-6271: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environm GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts execute
nvd