Lucene search

K
cveCertccCVE-2009-2629
HistorySep 15, 2009 - 10:30 p.m.

CVE-2009-2629

2009-09-1522:30:00
CWE-787
certcc
web.nvd.nist.gov
210
cve-2009-2629
buffer underflow
nvd
security
vulnerability
remote code execution
http requests

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.928

Percentile

99.0%

Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.

Affected configurations

Nvd
Node
f5nginxRange0.1.0–0.5.38
OR
f5nginxRange0.6.0–0.6.39
OR
f5nginxRange0.7.0–0.7.62
OR
f5nginxRange0.8.0–0.8.15
Node
debiandebian_linuxMatch4.0
OR
debiandebian_linuxMatch5.0
OR
debiandebian_linuxMatch6.0
Node
fedoraprojectfedoraMatch10
OR
fedoraprojectfedoraMatch11
OR
fedoraprojectfedoraMatch12

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.928

Percentile

99.0%