Vulnerability Details CVE-2016-4450
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.03
EPSS Ranking 85.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2016-4450
-
cpe:2.3:a:f5:nginx:1.10.0
-
cpe:2.3:a:f5:nginx:1.11.0
-
cpe:2.3:a:f5:nginx:1.3.10
-
cpe:2.3:a:f5:nginx:1.3.11
-
cpe:2.3:a:f5:nginx:1.3.12
-
cpe:2.3:a:f5:nginx:1.3.13
-
cpe:2.3:a:f5:nginx:1.3.14
-
cpe:2.3:a:f5:nginx:1.3.15
-
cpe:2.3:a:f5:nginx:1.3.16
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:f5:nginx:1.5.10
-
cpe:2.3:a:f5:nginx:1.5.11
-
cpe:2.3:a:f5:nginx:1.5.12
-
cpe:2.3:a:f5:nginx:1.5.13
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:f5:nginx:1.7.10
-
cpe:2.3:a:f5:nginx:1.7.11
-
cpe:2.3:a:f5:nginx:1.7.12
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:f5:nginx:1.9.10
-
cpe:2.3:a:f5:nginx:1.9.11
-
cpe:2.3:a:f5:nginx:1.9.12
-
cpe:2.3:a:f5:nginx:1.9.13
-
cpe:2.3:a:f5:nginx:1.9.14
-
cpe:2.3:a:f5:nginx:1.9.15
-
-
-
-
-
-
-
-
-
cpe:2.3:o:canonical:ubuntu_linux:14.04
-
cpe:2.3:o:canonical:ubuntu_linux:15.10
-
cpe:2.3:o:canonical:ubuntu_linux:16.04
-
cpe:2.3:o:debian:debian_linux:8.0