Skip to main content

Vendor/product archive

f5 / nginx CVEs

Beta · best-effort

40 CVEs tagged to f5 / nginx3 Critical, 18 High, 19 Medium, 0 Low, 0 Unrated.

CVE-2025-23419

Published Feb 5, 2025

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements o…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2017-20005

Published Jun 6, 2021

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-4968

Published Nov 19, 2019

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3556

Published Dec 29, 2014

The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3616

Published Dec 8, 2014

nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, wh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0088

Published Apr 29, 2014

The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0133

Published Mar 28, 2014

Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2