Vulnerabilities
Vulnerable Software
F5:  >> Nginx  >> 1.0.11  Security Vulnerabilities
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.
CVSS Score
4.3
EPSS Score
0.047
Published
2014-12-08
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
CVSS Score
7.5
EPSS Score
0.936
Published
2013-11-23
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
CVSS Score
7.5
EPSS Score
0.004
Published
2013-10-27
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
CVSS Score
5.0
EPSS Score
0.006
Published
2012-07-26
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
CVSS Score
5.0
EPSS Score
0.02
Published
2012-04-17
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
CVSS Score
6.8
EPSS Score
0.076
Published
2012-04-17


Contact Us

Shodan ® - All rights reserved