← All CVEs

CVE-2016-0742

high · 7.5

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

7.5
CVSS
82.0%
EPSS (exploit prob.)
100th
EPSS percentile
2016-02-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-476

Affected products

VendorProductAffected versions
f5nginx>= 0.6.18, < 1.8.1
f5nginx>= 1.9.0, < 1.9.10
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
debiandebian_linux7.0
debiandebian_linux8.0
debiandebian_linux9.0
opensuseleap42.1
applexcode< 13.0
redhatsoftware_collections1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-0742