FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-25 21:13:12 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
0882f019-bd60-11eb-9bdd-8c164567ca3cNGINX -- 1-byte memory overwrite in resolver

NGINX team reports:

1-byte memory overwrite might occur during DNS server response processing if the "resolver" directive was used, allowing an attacker who is able to forge UDP packets from the DNS server to cause worker process crash or, potentially, arbitrary code execution.


Discovery 2021-05-25
Entry 2021-05-25
nginx
< 1.20.1,2

nginx-devel
< 1.21.0

CVE-2021-23017
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23017
87679fcb-be60-11e9-9051-4c72b94353b5NGINX -- Multiple vulnerabilities

NGINX Team reports:

Several security issues were identified in nginx HTTP/2 implementation which might cause excessive memory consumption and CPU usage (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516). The issues affect nginx compiled with the ngx_http_v2_module (not compiled by default) if the http2 option of the listen directive is used in a configuration file.


Discovery 2019-08-13
Entry 2019-08-14
Modified 2019-08-14
nginx
< 1.16.1,2

nginx-devel
< 1.17.3

http://nginx.org/en/security_advisories.html
CVE-2019-9511
CVE-2019-9513
CVE-2019-9516
b28adc5b-6693-11e7-ad43-f0def16c5c1bnginx -- a specially crafted request might result in an integer overflow

Maxim Dounin reports:

A security issue was identified in nginx range filter. A specially crafted request might result in an integer overflow and incorrect processing of ranges, potentially resulting in sensitive information leak (CVE-2017-7529).


Discovery 2017-07-11
Entry 2017-07-11
nginx
ge 0.5.6 lt 1.12.1,2

nginx-devel
ge 0.5.6 lt 1.13.3

http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.html
CVE-2017-7529
c1202de8-4b29-11ea-9673-4c72b94353b5NGINX -- HTTP request smuggling

NGINX Team reports:

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.


Discovery 2019-12-10
Entry 2020-02-09
nginx
< 1.16.1_11,2

nginx-devel
< 1.17.7

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20372
CVE-2019-20372