CVE-2014-0133: F5 Nginx
High severity, CVSS 7.5. EPSS: 9.5% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.
Affected products
- F5 Nginx: from 1.3.15, before 1.4.7 (fixed in 1.4.7); from 1.5.0, up to and including 1.5.11
- Opensuse Opensuse: version 13.1 only
Published 2014-03-28. Last modified 2026-06-17.