F5

Nginx

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 92.54%
  • Veröffentlicht 20.07.2013 03:37:20
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which t...

  • EPSS 0.28%
  • Veröffentlicht 26.07.2012 19:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.

  • EPSS 4.87%
  • Veröffentlicht 17.04.2012 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly exe...

  • EPSS 1.98%
  • Veröffentlicht 17.04.2012 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.

  • EPSS 2.81%
  • Veröffentlicht 08.12.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.

  • EPSS 5.99%
  • Veröffentlicht 06.12.2010 21:05:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an uninte...

Exploit
  • EPSS 5.96%
  • Veröffentlicht 15.06.2010 14:04:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.

Exploit
  • EPSS 44.22%
  • Veröffentlicht 15.06.2010 14:04:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.

Exploit
  • EPSS 1.1%
  • Veröffentlicht 13.01.2010 20:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape seq...

Exploit
  • EPSS 1.08%
  • Veröffentlicht 24.11.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination...