F5 / Nginx
45 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-23419 | TLS Session Resumption Vulnerability | MEDIUM | 5.3 | Feb 5, 2025 |
| CVE-2024-34161 | NGINX HTTP/3 QUIC vulnerability | MEDIUM | 5.3 | May 29, 2024 |
| CVE-2024-35200 | NGINX HTTP/3 QUIC vulnerability | HIGH | 7.5 | May 29, 2024 |
| CVE-2024-32760 | NGINX HTTP/3 QUIC vulnerability | HIGH | 7.5 | May 29, 2024 |
| CVE-2024-31079 | NGINX HTTP/3 QUIC vulnerability | MEDIUM | 6.5 | May 29, 2024 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2022-41742 | NGINX ngx_http_mp4_module vulnerability CVE-2022-41742 | HIGH | 7.1 | Oct 19, 2022 |
| CVE-2022-41741 | NGINX ngx_http_mp4_module vulnerability CVE-2022-41741 | HIGH | 7.8 | Oct 19, 2022 |
| CVE-2021-3618 | ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication | HIGH | 7.4 | Mar 23, 2022 |
| CVE-2017-20005 | nginx: buffer overflow in ngx_gmtime() triggered by 5 digit years | CRITICAL | 9.8 | Jun 6, 2021 |
| CVE-2021-23017 | nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name | HIGH | 8.1 | Jun 1, 2021 |
| CVE-2019-20372 | nginx: HTTP request smuggling in configurations with URL redirect used as error_page | MEDIUM | 5.3 | Jan 9, 2020 |
| CVE-2011-4968 | nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) | MEDIUM | 4.8 | Nov 19, 2019 |
| CVE-2019-9516 | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service | MEDIUM | 6.5 | Aug 13, 2019 |
| CVE-2019-9513 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-9511 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2018-16845 | nginx: Denial of service and memory disclosure via mp4 module | MEDIUM | 6.1 | Nov 7, 2018 |
| CVE-2018-16844 | nginx: Excessive CPU usage via flaw in HTTP/2 implementation | HIGH | 7.5 | Nov 7, 2018 |
| CVE-2018-16843 | nginx: Excessive memory consumption via flaw in HTTP/2 implementation | HIGH | 7.5 | Nov 7, 2018 |
| CVE-2017-7529 | nginx: Integer overflow in nginx range filter module leading to memory disclosure | HIGH | 7.5 | Jul 13, 2017 |
| CVE-2016-1247 | nginx: Local privilege escalation via log files | HIGH | 7.8 | Nov 29, 2016 |
| CVE-2016-4450 | nginx: NULL pointer dereference while writing client request body | HIGH | 7.5 | Jun 7, 2016 |
| CVE-2016-0747 | nginx: Insufficient limits of CNAME resolution in resolver | MEDIUM | 5.3 | Feb 15, 2016 |
| CVE-2016-0746 | nginx: use-after-free during CNAME response processing in resolver | CRITICAL | 9.8 | Feb 15, 2016 |
| CVE-2016-0742 | nginx: invalid pointer dereference in resolver | HIGH | 7.5 | Feb 15, 2016 |
Showing 1 to 25 of 45 CVEs