rpm package
opensuse/nginx&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/nginx&distro=openSUSE%20Tumbleweed
Vulnerabilities (43)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2013-2070 | — | < 1.11.4-2.5 | 1.11.4-2.5 | Jul 20, 2013 | http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted p | ||
| CVE-2012-2089 | — | < 1.11.4-2.5 | 1.11.4-2.5 | Apr 17, 2012 | Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a craf | ||
| CVE-2011-4315 | — | < 1.11.4-2.5 | 1.11.4-2.5 | Dec 8, 2011 | Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response. |
- CVE-2013-2070Jul 20, 2013affected < 1.11.4-2.5fixed 1.11.4-2.5
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted p
- CVE-2012-2089Apr 17, 2012affected < 1.11.4-2.5fixed 1.11.4-2.5
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a craf
- CVE-2011-4315Dec 8, 2011affected < 1.11.4-2.5fixed 1.11.4-2.5
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
Page 3 of 3