← All CVEs

CVE-2009-3896

medium · 5

src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.

5
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2009-11-24
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
f5nginx0.1.0
f5nginx0.1.1
f5nginx0.1.2
f5nginx0.1.3
f5nginx0.1.4
f5nginx0.1.5
f5nginx0.1.6
f5nginx0.1.7
f5nginx0.1.8
f5nginx0.1.9
f5nginx0.1.10
f5nginx0.1.11
f5nginx0.1.12
f5nginx0.1.13
f5nginx0.1.14
f5nginx0.1.15
f5nginx0.1.16
f5nginx0.1.17
f5nginx0.1.18
f5nginx0.1.19
f5nginx0.1.20
f5nginx0.1.21
f5nginx0.1.22
f5nginx0.1.23
f5nginx0.1.24
f5nginx0.1.25
f5nginx0.1.26
f5nginx0.1.27
f5nginx0.1.28
f5nginx0.1.29
f5nginx0.1.30
f5nginx0.1.31
f5nginx0.1.32
f5nginx0.1.33
f5nginx0.1.34
f5nginx0.1.35
f5nginx0.1.36
f5nginx0.1.37
f5nginx0.1.38
f5nginx0.1.39

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-3896