CVE-2009-2629
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
- Affected products
- Nginx
- f5 Nginx
- < 0.5.38, 0.6.39, 0.7.62, 0.8.15
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 75.1% (99th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2009-09-15
CVE-2009-2629 at NVD
4 known exploits for CVE-2009-2629
Proof-of-concept code and exploit modules indexed by Sploitus