Show filters
894 Total Results
Displaying 241-250 of 894
Sort by:
Attacker Value
Unknown
CVE-2022-29480
Disclosure Date: May 04, 2022 (last updated February 23, 2025)
On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
0
Attacker Value
Unknown
CVE-2021-23055
Disclosure Date: April 21, 2022 (last updated February 23, 2025)
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
0
Attacker Value
Unknown
CVE-2022-28049
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c.
0
Attacker Value
Unknown
CVE-2022-27008
Disclosure Date: April 14, 2022 (last updated February 23, 2025)
nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array.
0
Attacker Value
Unknown
CVE-2022-27007
Disclosure Date: April 14, 2022 (last updated February 23, 2025)
nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save().
0
Attacker Value
Unknown
CVE-2021-3618
Disclosure Date: March 23, 2022 (last updated February 23, 2025)
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
0
Attacker Value
Unknown
CVE-2022-25139
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
0
Attacker Value
Unknown
CVE-2021-46463
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then().
0
Attacker Value
Unknown
CVE-2021-46462
Disclosure Date: February 14, 2022 (last updated October 07, 2023)
njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c.
0
Attacker Value
Unknown
CVE-2022-23032
Disclosure Date: January 25, 2022 (last updated February 23, 2025)
In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
0