Nginx

Nginx

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 27.09.2026 09:07:35
  • Zuletzt bearbeitet 02.10.2026 18:57:08

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_ce...

  • EPSS 0.18%
  • Veröffentlicht 10.04.2026 04:17:17
  • Zuletzt bearbeitet 27.04.2026 17:57:21

wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by ...

Exploit
  • EPSS 10.18%
  • Veröffentlicht 24.11.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:12:35

src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker p...

Exploit
  • EPSS 15.89%
  • Veröffentlicht 24.11.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:12:35

Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination...

  • EPSS 1.96%
  • Veröffentlicht 01.01.1999 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:48:39

A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.