Количество 14
Количество 14

CVE-2024-7347
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-7347
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-7347
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-7347
CVE-2024-7347
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_ ...

ROS-20240827-15
Уязвимость nginx
GHSA-3r23-64c4-mj87
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ELSA-2025-3262
ELSA-2025-3262: nginx:1.24 security update (MODERATE)
ELSA-2025-3261
ELSA-2025-3261: nginx:1.22 security update (MODERATE)

BDU:2024-06605
Уязвимость модуля ngx_http_v4_module веб-серверов NGINX Plus и NGINX OSS, связанная с чтением вне границ памяти, позволяющая нарушителю вызвать отказ в обслуживании

SUSE-SU-2025:0283-1
Security update for nginx

SUSE-SU-2025:0282-1
Security update for nginx

ROS-20241203-11
Уязвимость angie
ELSA-2025-7402
ELSA-2025-7402: nginx security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2024-7347 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.7 | 0% Низкий | 10 месяцев назад |
![]() | CVE-2024-7347 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.7 | 0% Низкий | 10 месяцев назад |
![]() | CVE-2024-7347 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.7 | 0% Низкий | 10 месяцев назад |
![]() | CVSS3: 4.7 | 0% Низкий | 8 месяцев назад | |
CVE-2024-7347 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_ ... | CVSS3: 4.7 | 0% Низкий | 10 месяцев назад | |
![]() | ROS-20240827-15 Уязвимость nginx | CVSS3: 4.7 | 0% Низкий | 10 месяцев назад |
GHSA-3r23-64c4-mj87 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.7 | 0% Низкий | 10 месяцев назад | |
ELSA-2025-3262 ELSA-2025-3262: nginx:1.24 security update (MODERATE) | 3 месяца назад | |||
ELSA-2025-3261 ELSA-2025-3261: nginx:1.22 security update (MODERATE) | 3 месяца назад | |||
![]() | BDU:2024-06605 Уязвимость модуля ngx_http_v4_module веб-серверов NGINX Plus и NGINX OSS, связанная с чтением вне границ памяти, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 4.7 | 0% Низкий | 10 месяцев назад |
![]() | SUSE-SU-2025:0283-1 Security update for nginx | 5 месяцев назад | ||
![]() | SUSE-SU-2025:0282-1 Security update for nginx | 5 месяцев назад | ||
![]() | ROS-20241203-11 Уязвимость angie | CVSS3: 4.7 | 0% Низкий | 7 месяцев назад |
ELSA-2025-7402 ELSA-2025-7402: nginx security update (MODERATE) | 29 дней назад |
Уязвимостей на страницу