Vulnerabilities
Vulnerable Software
F5:  >> Nginx  >> 1.0.5  Security Vulnerabilities
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
CVSS Score
7.5
EPSS Score
0.936
Published
2013-11-23
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
CVSS Score
7.5
EPSS Score
0.004
Published
2013-10-27
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
CVSS Score
5.0
EPSS Score
0.006
Published
2012-07-26
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
CVSS Score
5.0
EPSS Score
0.02
Published
2012-04-17
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
CVSS Score
6.8
EPSS Score
0.025
Published
2011-12-08


Contact Us

Shodan ® - All rights reserved