VYPR

rpm package

opensuse/nginx&distro=openSUSE Leap 15.0

pkg:rpm/opensuse/nginx&distro=openSUSE%20Leap%2015.0

Vulnerabilities (6)

  • CVE-2019-9516Aug 13, 2019
    affected < 1.14.2-lp150.2.11.1fixed 1.14.2-lp150.2.11.1

    Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations a

  • CVE-2019-9513Aug 13, 2019
    affected < 1.14.2-lp150.2.11.1fixed 1.14.2-lp150.2.11.1

    Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consu

  • CVE-2019-9511Aug 13, 2019
    affected < 1.14.2-lp150.2.11.1fixed 1.14.2-lp150.2.11.1

    Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and

  • CVE-2018-16845Nov 7, 2018
    affected < 1.14.2-16.1fixed 1.14.2-16.1

    nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.

  • CVE-2018-16844Nov 7, 2018
    affected < 1.14.2-16.1fixed 1.14.2-16.1

    nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a

  • CVE-2018-16843Nov 7, 2018
    affected < 1.14.2-16.1fixed 1.14.2-16.1

    nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is