Metrics
Affected Vendors & Products
Tue, 20 Aug 2024 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
F5
F5 nginx Open Source F5 nginx Plus |
|
Weaknesses | CWE-125 | |
CPEs | cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r31:p1:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r32:-:*:*:*:*:*:* |
|
Vendors & Products |
F5
F5 nginx Open Source F5 nginx Plus |
Fri, 16 Aug 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 14 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
ssvc
|
Wed, 14 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 14 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
Title | NGINX MP4 module vulnerability | |
Weaknesses | CWE-126 | |
References |
| |
Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: f5
Published: 2024-08-14T14:32:33.913Z
Updated: 2024-08-14T19:02:29.824Z
Reserved: 2024-07-31T17:59:09.786Z
Link: CVE-2024-7347
Updated: 2024-08-14T19:02:29.824Z
Status : Modified
Published: 2024-08-14T15:15:31.870
Modified: 2024-11-21T09:51:20.560
Link: CVE-2024-7347