Логотип exploitDog
bind:"CVE-2017-7529" OR bind:"CVE-2019-9511" OR bind:"CVE-2018-16845"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2017-7529" OR bind:"CVE-2019-9511" OR bind:"CVE-2018-16845"

Количество 46

Количество 46

oracle-oval логотип

ELSA-2020-5862

больше 4 лет назад

ELSA-2020-5862: olcne nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5859

больше 4 лет назад

ELSA-2020-5859: olcne nginx security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2017-7529

почти 8 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2017-7529

почти 8 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 5.3
EPSS: Критический
nvd логотип

CVE-2017-7529

почти 8 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2017-7529

почти 8 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable t ...

CVSS3: 7.5
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2018:0823-1

около 7 лет назад

Security update for nginx

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2017:2003-1

почти 8 лет назад

Security update for nginx

EPSS: Критический
github логотип

GHSA-85mj-h68w-w736

около 3 лет назад

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
EPSS: Критический
fstec логотип

BDU:2021-03045

почти 8 лет назад

Уязвимость модуля фильтра диапазона nginx HTTP-сервера nginx, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2019:2120-1

почти 6 лет назад

Security update for nginx

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2309-1

почти 6 лет назад

Security update for nginx

EPSS: Низкий
ubuntu логотип

CVE-2018-16845

больше 6 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-16845

больше 6 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2018-16845

больше 6 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-16845

больше 6 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_ht ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-9511

почти 6 лет назад

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-9511

почти 6 лет назад

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-9511

почти 6 лет назад

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2019-9511

почти 6 лет назад

HTTP/2 Server Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-5862

ELSA-2020-5862: olcne nginx security update (IMPORTANT)

больше 4 лет назад
oracle-oval логотип
ELSA-2020-5859

ELSA-2020-5859: olcne nginx security update (IMPORTANT)

больше 4 лет назад
ubuntu логотип
CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
92%
Критический
почти 8 лет назад
redhat логотип
CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 5.3
92%
Критический
почти 8 лет назад
nvd логотип
CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
92%
Критический
почти 8 лет назад
debian логотип
CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable t ...

CVSS3: 7.5
92%
Критический
почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0823-1

Security update for nginx

92%
Критический
около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2003-1

Security update for nginx

92%
Критический
почти 8 лет назад
github логотип
GHSA-85mj-h68w-w736

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

CVSS3: 7.5
92%
Критический
около 3 лет назад
fstec логотип
BDU:2021-03045

Уязвимость модуля фильтра диапазона nginx HTTP-сервера nginx, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
92%
Критический
почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2120-1

Security update for nginx

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2309-1

Security update for nginx

почти 6 лет назад
ubuntu логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
5%
Низкий
больше 6 лет назад
redhat логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 8.2
5%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
5%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_ht ...

CVSS3: 6.1
5%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
14%
Средний
почти 6 лет назад
redhat логотип
CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 6.5
14%
Средний
почти 6 лет назад
nvd логотип
CVE-2019-9511

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS3: 7.5
14%
Средний
почти 6 лет назад
msrc логотип
CVE-2019-9511

HTTP/2 Server Denial of Service Vulnerability

CVSS3: 7.5
14%
Средний
почти 6 лет назад

Уязвимостей на страницу