CVE-2026-5501
- EPSS 0.02%
- Veröffentlicht 10.04.2026 04:17:17
- Zuletzt bearbeitet 27.04.2026 17:57:21
wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by ...
- EPSS 2.51%
- Veröffentlicht 24.11.2009 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker p...
CVE-2009-3898
- EPSS 1.08%
- Veröffentlicht 24.11.2009 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination...
- EPSS 0.47%
- Veröffentlicht 01.01.1999 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.