CVE-2013-2028
- EPSS 92.54%
- Published 20.07.2013 03:37:20
- Last modified 11.04.2025 00:51:21
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which t...
- EPSS 0.28%
- Published 26.07.2012 19:55:00
- Last modified 11.04.2025 00:51:21
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
CVE-2012-2089
- EPSS 4.87%
- Published 17.04.2012 21:55:01
- Last modified 11.04.2025 00:51:21
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly exe...
- EPSS 1.98%
- Published 17.04.2012 21:55:01
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
CVE-2011-4315
- EPSS 2.81%
- Published 08.12.2011 20:55:01
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
CVE-2010-4180
- EPSS 5.99%
- Published 06.12.2010 21:05:48
- Last modified 11.04.2025 00:51:21
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an uninte...
- EPSS 5.96%
- Published 15.06.2010 14:04:24
- Last modified 11.04.2025 00:51:21
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
- EPSS 44.22%
- Published 15.06.2010 14:04:24
- Last modified 11.04.2025 00:51:21
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
CVE-2009-4487
- EPSS 1.1%
- Published 13.01.2010 20:30:00
- Last modified 09.04.2025 00:30:58
nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape seq...
CVE-2009-3898
- EPSS 1.08%
- Published 24.11.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination...