CVE-2017-7529

HIGH LAB

Nginx <1.14 - Info Disclosure

Title source: llm

Description

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

Exploits (16)

nomisec WORKING POC 19 stars
by en0f · poc
https://github.com/en0f/CVE-2017-7529_PoC
nomisec WORKING POC 16 stars
by liusec · poc
https://github.com/liusec/CVE-2017-7529
nomisec WORKING POC 10 stars
by Shehzadcyber · poc
https://github.com/Shehzadcyber/CVE-2017-7529
nomisec WORKING POC 9 stars
by gemboxteam · poc
https://github.com/gemboxteam/exploit-nginx-1.10.3
nomisec WORKING POC 4 stars
by MaxSecurity · poc
https://github.com/MaxSecurity/CVE-2017-7529-POC
nomisec WORKING POC 2 stars
by cyberharsh · poc
https://github.com/cyberharsh/nginx-CVE-2017-7529
nomisec WORKING POC 1 stars
by coolman6942o · poc
https://github.com/coolman6942o/-Exploit-CVE-2017-7529
nomisec WORKING POC 1 stars
by insecrez · poc
https://github.com/insecrez/Remote-Integer-Overflow-Vulnerability
nomisec WORKING POC 1 stars
by mo3zj · poc
https://github.com/mo3zj/Nginx-Remote-Integer-Overflow-Vulnerability
nomisec WORKING POC
by portfolio10 · poc
https://github.com/portfolio10/nginx
nomisec WORKING POC
by youngmin0104 · poc
https://github.com/youngmin0104/CVE-2017-7529-
nomisec WORKING POC
by Fenil2511 · poc
https://github.com/Fenil2511/CVE-2017-7529-POC
nomisec WORKING POC
by fu2x2000 · poc
https://github.com/fu2x2000/CVE-2017-7529-Nginx---Remote-Integer-Overflow-Exploit
nomisec STUB
by cved-sources · poc
https://github.com/cved-sources/cve-2017-7529
nomisec SCANNER
by daehee · poc
https://github.com/daehee/nginx-overflow
nomisec WORKING POC
by cyberk1w1 · poc
https://github.com/cyberk1w1/CVE-2017-7529

Scores

CVSS v3 7.5
EPSS 0.9191
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull nginx:1.13.1
docker pull vulhub/nginx:1.13.2
docker pull nginx:1.12
+13 more repos

Details

CWE
CWE-190
Status published
Products (4)
apple/xcode < 13.0
f5/nginx 0.5.6 - 1.12.1
nginx/nginx 0.5.6 - 1.13.2
puppet/puppet_enterprise < 2016.4.7
Published Jul 13, 2017
Tracked Since Feb 18, 2026