CVE-2014-0133: F5 Nginx

High severity, CVSS 7.5. EPSS: 9.5% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.

Affected products

  • F5 Nginx: from 1.3.15, before 1.4.7 (fixed in 1.4.7); from 1.5.0, up to and including 1.5.11
  • Opensuse Opensuse: version 13.1 only

Published 2014-03-28. Last modified 2026-06-17.