Логотип exploitDog
bind:CVE-2018-16845
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-16845

Количество 12

Количество 12

ubuntu логотип

CVE-2018-16845

больше 6 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-16845

больше 6 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2018-16845

больше 6 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-16845

больше 6 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_ht ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vq5f-vpgw-9vcp

около 3 лет назад

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2019-00984

больше 6 лет назад

Уязвимость модуля ngx_http_mp4_module сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании или раскрыть защищаемую информацию

CVSS3: 5.4
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:0195-1

около 6 лет назад

Security update for nginx

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0334-1

больше 6 лет назад

Security update for nginx

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5862

больше 4 лет назад

ELSA-2020-5862: olcne nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5859

больше 4 лет назад

ELSA-2020-5859: olcne nginx security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2120-1

почти 6 лет назад

Security update for nginx

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2309-1

почти 6 лет назад

Security update for nginx

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
5%
Низкий
больше 6 лет назад
redhat логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 8.2
5%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
5%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-16845

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_ht ...

CVSS3: 6.1
5%
Низкий
больше 6 лет назад
github логотип
GHSA-vq5f-vpgw-9vcp

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

CVSS3: 6.1
5%
Низкий
около 3 лет назад
fstec логотип
BDU:2019-00984

Уязвимость модуля ngx_http_mp4_module сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании или раскрыть защищаемую информацию

CVSS3: 5.4
5%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:0195-1

Security update for nginx

около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:0334-1

Security update for nginx

больше 6 лет назад
oracle-oval логотип
ELSA-2020-5862

ELSA-2020-5862: olcne nginx security update (IMPORTANT)

больше 4 лет назад
oracle-oval логотип
ELSA-2020-5859

ELSA-2020-5859: olcne nginx security update (IMPORTANT)

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2120-1

Security update for nginx

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2309-1

Security update for nginx

почти 6 лет назад

Уязвимостей на страницу