Логотип exploitDog
bind:"CVE-2017-7529" OR bind:"CVE-2019-9511" OR bind:"CVE-2018-16845"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2017-7529" OR bind:"CVE-2019-9511" OR bind:"CVE-2018-16845"

Количество 46

Количество 46

oracle-oval логотип

ELSA-2020-5862

около 5 лет назад

ELSA-2020-5862: olcne nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5859

около 5 лет назад

ELSA-2020-5859: olcne nginx security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2017-7529

больше 8 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2017-7529

больше 8 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 5.3
EPSS: Критический
nvd логотип

CVE-2017-7529

больше 8 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2017-7529

больше 8 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable t ...

CVSS3: 7.5
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2018:0823-1

больше 7 лет назад

Security update for nginx

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2017:2003-1

больше 8 лет назад

Security update for nginx

EPSS: Критический
github логотип

GHSA-85mj-h68w-w736

больше 3 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
EPSS: Критический
fstec логотип

BDU:2021-03045

больше 8 лет назад

Уязвимость модуля фильтра диапазона nginx HTTP-сервера nginx, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2019:2120-1

около 6 лет назад

Security update for nginx

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2309-1

около 6 лет назад

Security update for nginx

EPSS: Низкий
ubuntu логотип

CVE-2018-16845

почти 7 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-16845

почти 7 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2018-16845

почти 7 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-16845

почти 7 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_ht ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-9511

около 6 лет назад

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-9511

около 6 лет назад

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-9511

около 6 лет назад

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2019-9511

около 6 лет назад

HTTP/2 Server Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-5862

ELSA-2020-5862: olcne nginx security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5859

ELSA-2020-5859: olcne nginx security update (IMPORTANT)

около 5 лет назад
ubuntu логотип
CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
92%
Критический
больше 8 лет назад
redhat логотип
CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 5.3
92%
Критический
больше 8 лет назад
nvd логотип
CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
92%
Критический
больше 8 лет назад
debian логотип
CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable t ...

CVSS3: 7.5
92%
Критический
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0823-1

Security update for nginx

92%
Критический
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2003-1

Security update for nginx

92%
Критический
больше 8 лет назад
github логотип
GHSA-85mj-h68w-w736

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
92%
Критический
больше 3 лет назад
fstec логотип
BDU:2021-03045

Уязвимость модуля фильтра диапазона nginx HTTP-сервера nginx, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
92%
Критический
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2120-1

Security update for nginx

около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2309-1

Security update for nginx

около 6 лет назад
ubuntu логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 8.2
4%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
4%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_ht ...

CVSS3: 6.1
4%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
14%
Средний
около 6 лет назад
redhat логотип
CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 6.5
14%
Средний
около 6 лет назад
nvd логотип
CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
14%
Средний
около 6 лет назад
msrc логотип
CVE-2019-9511

HTTP/2 Server Denial of Service Vulnerability

CVSS3: 7.5
14%
Средний
около 6 лет назад

Уязвимостей на страницу