Description
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Exploits (16)
nomisec
WORKING POC
1 stars
by coolman6942o · poc
https://github.com/coolman6942o/-Exploit-CVE-2017-7529
nomisec
WORKING POC
1 stars
by insecrez · poc
https://github.com/insecrez/Remote-Integer-Overflow-Vulnerability
nomisec
WORKING POC
1 stars
by mo3zj · poc
https://github.com/mo3zj/Nginx-Remote-Integer-Overflow-Vulnerability
nomisec
WORKING POC
by fu2x2000 · poc
https://github.com/fu2x2000/CVE-2017-7529-Nginx---Remote-Integer-Overflow-Exploit
References (7)
Scores
CVSS v3
7.5
EPSS
0.9191
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Lab Environment
COMMUNITY
Community Lab
+13 more repos
Details
CWE
CWE-190
Status
published
Products (4)
apple/xcode
< 13.0
f5/nginx
0.5.6 - 1.12.1
nginx/nginx
0.5.6 - 1.13.2
puppet/puppet_enterprise
< 2016.4.7
Published
Jul 13, 2017
Tracked Since
Feb 18, 2026