Lucene search

K
nginxNginxNGINX:CVE-2012-1180
HistoryApr 17, 2012 - 9:55 p.m.

Memory disclosure with specially crafted backend responses

2012-04-1721:55:01
mailman.nginx.org
181

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

59.5%

Memory disclosure with specially crafted backend responses
Severity: major
CVE-2012-1180
Not vulnerable: 1.1.17+, 1.0.14+
Vulnerable: 0.1.0-1.1.16

Affected configurations

Vulners
Node
f5nginxRange0.1.0–1.1.16
VendorProductVersionCPE
f5nginx*cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

59.5%