CVE-2011-4968
- EPSS 0.27%
- Veröffentlicht 19.11.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 01:33:23
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
CVE-2019-9516
- EPSS 2.29%
- Veröffentlicht 13.08.2019 21:15:12
- Zuletzt bearbeitet 14.01.2025 19:29:55
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater h...
CVE-2019-9513
- EPSS 4.36%
- Veröffentlicht 13.08.2019 21:15:12
- Zuletzt bearbeitet 14.01.2025 19:29:55
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the...
CVE-2019-9511
- EPSS 13.95%
- Veröffentlicht 13.08.2019 21:15:12
- Zuletzt bearbeitet 14.01.2025 19:29:55
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. T...
CVE-2018-16845
- EPSS 4.03%
- Veröffentlicht 07.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:25
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using ...
CVE-2018-16844
- EPSS 10.88%
- Veröffentlicht 07.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:25
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the '...
CVE-2018-16843
- EPSS 55.54%
- Veröffentlicht 07.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:25
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option...
CVE-2017-7529
- EPSS 91.91%
- Veröffentlicht 13.07.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
CVE-2016-1247
- EPSS 9.86%
- Veröffentlicht 29.11.2016 17:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1....
CVE-2016-4450
- EPSS 4.09%
- Veröffentlicht 07.06.2016 14:06:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary...