Lucene search

K
nvd[email protected]NVD:CVE-2009-3896
HistoryNov 24, 2009 - 5:30 p.m.

CVE-2009-3896

2009-11-2417:30:00
CWE-119
web.nvd.nist.gov
1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

High

0.086 Low

EPSS

Percentile

94.5%

src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.

Affected configurations

NVD
Node
f5nginxMatch0.1.0
OR
f5nginxMatch0.1.1
OR
f5nginxMatch0.1.2
OR
f5nginxMatch0.1.3
OR
f5nginxMatch0.1.4
OR
f5nginxMatch0.1.5
OR
f5nginxMatch0.1.6
OR
f5nginxMatch0.1.7
OR
f5nginxMatch0.1.8
OR
f5nginxMatch0.1.9
OR
f5nginxMatch0.1.10
OR
f5nginxMatch0.1.11
OR
f5nginxMatch0.1.12
OR
f5nginxMatch0.1.13
OR
f5nginxMatch0.1.14
OR
f5nginxMatch0.1.15
OR
f5nginxMatch0.1.16
OR
f5nginxMatch0.1.17
OR
f5nginxMatch0.1.18
OR
f5nginxMatch0.1.19
OR
f5nginxMatch0.1.20
OR
f5nginxMatch0.1.21
OR
f5nginxMatch0.1.22
OR
f5nginxMatch0.1.23
OR
f5nginxMatch0.1.24
OR
f5nginxMatch0.1.25
OR
f5nginxMatch0.1.26
OR
f5nginxMatch0.1.27
OR
f5nginxMatch0.1.28
OR
f5nginxMatch0.1.29
OR
f5nginxMatch0.1.30
OR
f5nginxMatch0.1.31
OR
f5nginxMatch0.1.32
OR
f5nginxMatch0.1.33
OR
f5nginxMatch0.1.34
OR
f5nginxMatch0.1.35
OR
f5nginxMatch0.1.36
OR
f5nginxMatch0.1.37
OR
f5nginxMatch0.1.38
OR
f5nginxMatch0.1.39
OR
f5nginxMatch0.1.40
OR
f5nginxMatch0.1.41
OR
f5nginxMatch0.1.42
OR
f5nginxMatch0.1.43
OR
f5nginxMatch0.1.44
OR
f5nginxMatch0.1.45
OR
f5nginxMatch0.2.0
OR
f5nginxMatch0.2.1
OR
f5nginxMatch0.2.2
OR
f5nginxMatch0.2.3
OR
f5nginxMatch0.2.4
OR
f5nginxMatch0.2.5
OR
f5nginxMatch0.2.6
OR
f5nginxMatch0.3.0
OR
f5nginxMatch0.3.1
OR
f5nginxMatch0.3.2
OR
f5nginxMatch0.3.3
OR
f5nginxMatch0.3.4
OR
f5nginxMatch0.3.5
OR
f5nginxMatch0.3.6
OR
f5nginxMatch0.3.7
OR
f5nginxMatch0.3.8
OR
f5nginxMatch0.3.9
OR
f5nginxMatch0.3.10
OR
f5nginxMatch0.3.11
OR
f5nginxMatch0.3.12
OR
f5nginxMatch0.3.13
OR
f5nginxMatch0.3.14
OR
f5nginxMatch0.3.15
OR
f5nginxMatch0.3.16
OR
f5nginxMatch0.3.17
OR
f5nginxMatch0.3.18
OR
f5nginxMatch0.3.19
OR
f5nginxMatch0.3.20
OR
f5nginxMatch0.3.21
OR
f5nginxMatch0.3.22
OR
f5nginxMatch0.3.23
OR
f5nginxMatch0.3.24
OR
f5nginxMatch0.3.25
OR
f5nginxMatch0.3.26
OR
f5nginxMatch0.3.27
OR
f5nginxMatch0.3.28
OR
f5nginxMatch0.3.29
OR
f5nginxMatch0.3.30
OR
f5nginxMatch0.3.31
OR
f5nginxMatch0.3.32
OR
f5nginxMatch0.3.33
OR
f5nginxMatch0.3.34
OR
f5nginxMatch0.3.35
OR
f5nginxMatch0.3.36
OR
f5nginxMatch0.3.37
OR
f5nginxMatch0.3.38
OR
f5nginxMatch0.3.39
OR
f5nginxMatch0.3.40
OR
f5nginxMatch0.3.41
OR
f5nginxMatch0.3.42
OR
f5nginxMatch0.3.43
OR
f5nginxMatch0.3.44
OR
f5nginxMatch0.3.45
OR
f5nginxMatch0.3.46
OR
f5nginxMatch0.3.47
OR
f5nginxMatch0.3.48
OR
f5nginxMatch0.3.49
OR
f5nginxMatch0.3.50
OR
f5nginxMatch0.3.51
OR
f5nginxMatch0.3.52
OR
f5nginxMatch0.3.53
OR
f5nginxMatch0.3.54
OR
f5nginxMatch0.3.55
OR
f5nginxMatch0.3.56
OR
f5nginxMatch0.3.57
OR
f5nginxMatch0.3.58
OR
f5nginxMatch0.3.59
OR
f5nginxMatch0.3.60
OR
f5nginxMatch0.3.61
OR
f5nginxMatch0.4.0
OR
f5nginxMatch0.4.1
OR
f5nginxMatch0.4.2
OR
f5nginxMatch0.4.3
OR
f5nginxMatch0.4.4
OR
f5nginxMatch0.4.5
OR
f5nginxMatch0.4.6
OR
f5nginxMatch0.4.7
OR
f5nginxMatch0.4.8
OR
f5nginxMatch0.4.9
OR
f5nginxMatch0.4.10
OR
f5nginxMatch0.4.11
OR
f5nginxMatch0.4.12
OR
f5nginxMatch0.4.13
OR
f5nginxMatch0.5.0
OR
f5nginxMatch0.5.1
OR
f5nginxMatch0.5.2
OR
f5nginxMatch0.5.3
OR
f5nginxMatch0.5.4
OR
f5nginxMatch0.5.5
OR
f5nginxMatch0.5.6
OR
f5nginxMatch0.5.7
OR
f5nginxMatch0.5.8
OR
f5nginxMatch0.5.9
OR
f5nginxMatch0.5.10
OR
f5nginxMatch0.5.11
OR
f5nginxMatch0.5.12
OR
f5nginxMatch0.5.13
OR
f5nginxMatch0.5.14
OR
f5nginxMatch0.5.15
OR
f5nginxMatch0.5.16
OR
f5nginxMatch0.5.17
OR
f5nginxMatch0.5.18
OR
f5nginxMatch0.5.19
OR
f5nginxMatch0.5.20
OR
f5nginxMatch0.5.21
OR
f5nginxMatch0.5.22
OR
f5nginxMatch0.5.23
OR
f5nginxMatch0.5.24
OR
f5nginxMatch0.5.25
OR
f5nginxMatch0.5.26
OR
f5nginxMatch0.5.27
OR
f5nginxMatch0.5.28
OR
f5nginxMatch0.5.29
OR
f5nginxMatch0.5.30
OR
f5nginxMatch0.5.31
OR
f5nginxMatch0.5.32
OR
f5nginxMatch0.5.33
OR
f5nginxMatch0.5.34
OR
f5nginxMatch0.5.35
OR
f5nginxMatch0.5.36
OR
f5nginxMatch0.5.37
OR
f5nginxMatch0.6.0
OR
f5nginxMatch0.6.1
OR
f5nginxMatch0.6.2
OR
f5nginxMatch0.6.3
OR
f5nginxMatch0.6.4
OR
f5nginxMatch0.6.5
OR
f5nginxMatch0.6.6
OR
f5nginxMatch0.6.7
OR
f5nginxMatch0.6.8
OR
f5nginxMatch0.6.9
OR
f5nginxMatch0.6.10
OR
f5nginxMatch0.6.11
OR
f5nginxMatch0.6.12
OR
f5nginxMatch0.6.13
OR
f5nginxMatch0.6.14
OR
f5nginxMatch0.6.15
OR
f5nginxMatch0.6.17
OR
f5nginxMatch0.6.18
OR
f5nginxMatch0.6.19
OR
f5nginxMatch0.6.20
OR
f5nginxMatch0.6.21
OR
f5nginxMatch0.6.22
OR
f5nginxMatch0.6.23
OR
f5nginxMatch0.6.24
OR
f5nginxMatch0.6.25
OR
f5nginxMatch0.6.26
OR
f5nginxMatch0.6.27
OR
f5nginxMatch0.6.28
OR
f5nginxMatch0.6.29
OR
f5nginxMatch0.6.30
OR
f5nginxMatch0.6.31
OR
f5nginxMatch0.6.32
OR
f5nginxMatch0.6.33
OR
f5nginxMatch0.6.34
OR
f5nginxMatch0.6.35
OR
f5nginxMatch0.6.36
OR
f5nginxMatch0.6.37
OR
f5nginxMatch0.6.38
OR
f5nginxMatch0.7.0
OR
f5nginxMatch0.7.1
OR
f5nginxMatch0.7.2
OR
f5nginxMatch0.7.3
OR
f5nginxMatch0.7.4
OR
f5nginxMatch0.7.5
OR
f5nginxMatch0.7.6
OR
f5nginxMatch0.7.7
OR
f5nginxMatch0.7.8
OR
f5nginxMatch0.7.9
OR
f5nginxMatch0.7.10
OR
f5nginxMatch0.7.11
OR
f5nginxMatch0.7.12
OR
f5nginxMatch0.7.13
OR
f5nginxMatch0.7.14
OR
f5nginxMatch0.7.15
OR
f5nginxMatch0.7.16
OR
f5nginxMatch0.7.17
OR
f5nginxMatch0.7.18
OR
f5nginxMatch0.7.19
OR
f5nginxMatch0.7.20
OR
f5nginxMatch0.7.21
OR
f5nginxMatch0.7.22
OR
f5nginxMatch0.7.23
OR
f5nginxMatch0.7.24
OR
f5nginxMatch0.7.25
OR
f5nginxMatch0.7.26
OR
f5nginxMatch0.7.27
OR
f5nginxMatch0.7.28
OR
f5nginxMatch0.7.29
OR
f5nginxMatch0.7.30
OR
f5nginxMatch0.7.31
OR
f5nginxMatch0.7.32
OR
f5nginxMatch0.7.33
OR
f5nginxMatch0.7.34
OR
f5nginxMatch0.7.35
OR
f5nginxMatch0.7.36
OR
f5nginxMatch0.7.37
OR
f5nginxMatch0.7.38
OR
f5nginxMatch0.7.39
OR
f5nginxMatch0.7.40
OR
f5nginxMatch0.7.41
OR
f5nginxMatch0.7.42
OR
f5nginxMatch0.7.43
OR
f5nginxMatch0.7.44
OR
f5nginxMatch0.7.45
OR
f5nginxMatch0.7.46
OR
f5nginxMatch0.7.47
OR
f5nginxMatch0.7.48
OR
f5nginxMatch0.7.49
OR
f5nginxMatch0.7.50
OR
f5nginxMatch0.7.51
OR
f5nginxMatch0.7.52
OR
f5nginxMatch0.7.53
OR
f5nginxMatch0.7.54
OR
f5nginxMatch0.7.55
OR
f5nginxMatch0.7.56
OR
f5nginxMatch0.7.57
OR
f5nginxMatch0.7.58
OR
f5nginxMatch0.7.59
OR
f5nginxMatch0.7.60
OR
f5nginxMatch0.7.61
OR
f5nginxMatch0.8.0
OR
f5nginxMatch0.8.1
OR
f5nginxMatch0.8.2
OR
f5nginxMatch0.8.3
OR
f5nginxMatch0.8.4
OR
f5nginxMatch0.8.5
OR
f5nginxMatch0.8.6
OR
f5nginxMatch0.8.7
OR
f5nginxMatch0.8.8
OR
f5nginxMatch0.8.9
OR
f5nginxMatch0.8.10
OR
f5nginxMatch0.8.11
OR
f5nginxMatch0.8.12
OR
f5nginxMatch0.8.13
OR
f5nginxMatch0.8.14
OR
nginxnginxMatch0.6.1516

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

High

0.086 Low

EPSS

Percentile

94.5%