Логотип exploitDog
bind:CVE-2026-32647
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-32647

Количество 16

Количество 16

ubuntu логотип

CVE-2026-32647

около 1 месяца назад

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-32647

около 1 месяца назад

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-32647

около 1 месяца назад

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-32647

около 1 месяца назад

NGINX ngx_http_mp4_module vulnerability

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-32647

около 1 месяца назад

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_ ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-6364-x4qj-7w59

около 1 месяца назад

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2026-04819

около 1 месяца назад

Уязвимость модуля ngx_http_mp4_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2026:7343

27 дней назад

Important: nginx:1.26 security update

EPSS: Низкий
rocky логотип

RLSA-2026:6923

29 дней назад

Important: nginx:1.24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:6907

27 дней назад

Important: nginx:1.24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:6906

27 дней назад

Important: nginx security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7343

26 дней назад

ELSA-2026-7343: nginx:1.26 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7002

29 дней назад

ELSA-2026-7002: nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6923

29 дней назад

ELSA-2026-6923: nginx:1.24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6907

29 дней назад

ELSA-2026-6907: nginx:1.24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6906

30 дней назад

ELSA-2026-6906: nginx security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-32647

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-32647

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-32647

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-32647

NGINX ngx_http_mp4_module vulnerability

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-32647

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_ ...

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-6364-x4qj-7w59

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-04819

Уязвимость модуля ngx_http_mp4_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:7343

Important: nginx:1.26 security update

27 дней назад
rocky логотип
RLSA-2026:6923

Important: nginx:1.24 security update

29 дней назад
rocky логотип
RLSA-2026:6907

Important: nginx:1.24 security update

27 дней назад
rocky логотип
RLSA-2026:6906

Important: nginx security update

27 дней назад
oracle-oval логотип
ELSA-2026-7343

ELSA-2026-7343: nginx:1.26 security update (IMPORTANT)

26 дней назад
oracle-oval логотип
ELSA-2026-7002

ELSA-2026-7002: nginx security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2026-6923

ELSA-2026-6923: nginx:1.24 security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2026-6907

ELSA-2026-6907: nginx:1.24 security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2026-6906

ELSA-2026-6906: nginx security update (IMPORTANT)

30 дней назад

Уязвимостей на страницу