Vulnerability Details CVE-2016-0747
                The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.363
                        
                    
                    
                        
                            EPSS Ranking 96.9%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 5.3
                        
                    
                    
                        
                            CVSS v2 Score 5.0