7.5

CVE-2013-0337

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.

Data is provided by the National Vulnerability Database (NVD)
F5Nginx Version <= 1.3.13
F5Nginx Version1.0.0
F5Nginx Version1.0.1
F5Nginx Version1.0.2
F5Nginx Version1.0.3
F5Nginx Version1.0.4
F5Nginx Version1.0.5
F5Nginx Version1.0.6
F5Nginx Version1.0.7
F5Nginx Version1.0.8
F5Nginx Version1.0.9
F5Nginx Version1.0.10
F5Nginx Version1.0.11
F5Nginx Version1.0.12
F5Nginx Version1.0.13
F5Nginx Version1.0.14
F5Nginx Version1.0.15
F5Nginx Version1.1.0
F5Nginx Version1.1.1
F5Nginx Version1.1.2
F5Nginx Version1.1.3
F5Nginx Version1.1.4
F5Nginx Version1.1.5
F5Nginx Version1.1.6
F5Nginx Version1.1.7
F5Nginx Version1.1.8
F5Nginx Version1.1.9
F5Nginx Version1.1.10
F5Nginx Version1.1.11
F5Nginx Version1.1.12
F5Nginx Version1.1.13
F5Nginx Version1.1.14
F5Nginx Version1.1.15
F5Nginx Version1.1.16
F5Nginx Version1.1.17
F5Nginx Version1.1.18
F5Nginx Version1.1.19
F5Nginx Version1.2.0
F5Nginx Version1.3.0
F5Nginx Version1.3.1
F5Nginx Version1.3.2
F5Nginx Version1.3.3
F5Nginx Version1.3.4
F5Nginx Version1.3.5
F5Nginx Version1.3.6
F5Nginx Version1.3.7
F5Nginx Version1.3.8
F5Nginx Version1.3.9
F5Nginx Version1.3.10
F5Nginx Version1.3.11
F5Nginx Version1.3.12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.55% 0.671
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P