← All CVEs

CVE-2017-7529

high · 7.5

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

7.5
CVSS
62.6%
EPSS (exploit prob.)
99th
EPSS percentile
2017-07-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
f5nginx>= 0.5.6, <= 1.12.1
f5nginx>= 1.13.0, <= 1.13.2
puppetpuppet_enterprise< 2016.4.7
puppetpuppet_enterprise>= 2017.1.0, <= 2017.1.1
puppetpuppet_enterprise>= 2017.2.1, <= 2017.2.3
applexcode< 13.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-7529