F5
Vulnerabilities in F5 BIG-IP's iControl REST and TMUI management interfaces — application-delivery controllers whose compromise typically hands attackers control of the load-balanced traffic behind them.
nginx map directive regex-capture heap buffer overflow in worker
A heap buffer overflow in the nginx worker process when a map directive's string expression references its regex capture variables before the output variable. Reachable via crafted HTTP; DoS by worker restart, code execution possible only where ASLR is disabled or bypassable.
F5 BIG-IP iControl REST Authentication Bypass
An authentication-bypass vulnerability in the F5 BIG-IP iControl REST API allows an unauthenticated attacker with network access to the management interface or self-IP addresses to execute arbitrary system commands, create or delete files, or disable services.