Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nginx | Jul 30, 2024 | Mar 28, 2014 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | Dec 10, 2025 | Mar 23, 2014 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Mar 28, 2014 |
| Nginx | — | Upgrade to nginx version 1.5.12Upgrade to nginx version 1.4.7 | Apr 10, 2014 | Mar 28, 2014 |
| Suse | — | Upgrade nginx | Dec 18, 2015 | Mar 26, 2014 |
| Ubuntu | — | Upgrade nginx | Nov 19, 2024 | Mar 28, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub