Lucene search

K
nginxNginxNGINX:CVE-2014-0088
HistoryApr 29, 2014 - 2:38 p.m.

SPDY memory corruption

2014-04-2914:38:49
mailman.nginx.org
151

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

86.9%

SPDY memory corruption
Severity: major
CVE-2014-0088
Not vulnerable: 1.5.11+
Vulnerable: 1.5.10

Affected configurations

Vulners
Node
f5nginx
VendorProductVersionCPE
f5nginx*cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

86.9%