← Vulnerability feed

Vulnerability record · CVE-2014-0088 · published 29 April 2014

CVE-2014-0088: F5 nginx memory buffer overflow vulnerability

F5 · Nginx

The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.

7.5 CVSS 2.0 High EPSS 8.7% · top 5.1% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
8.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0088 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2017-20005F5 nginx integer overflow vulnerabilityNGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes a…EPSS 3.3%9.8CVE-2016-0746F5 nginx use after free vulnerabilityUse-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of servi…EPSS 8.9%9.8CVE-2009-3555TLS/SSL renegotiation flaw allows plaintext injection into sessionsThe TLS protocol and SSL 3.0 do not properly bind renegotiation handshakes to the existing connection, so a man-in-the-middle can inject data that th…EPSS 87%analysed7.8CVE-2022-41741F5 nginx out-of-bounds write vulnerabilityNGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R…EPSS 0.79%7.8CVE-2016-1247F5 nginx link following vulnerabilityThe nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.0…EPSS 4.9%7.7CVE-2021-23017nginx resolver off-by-one allows 1-byte memory overwrite via forged DNS responseThe nginx resolver contains an off-by-one error (CWE-193) that lets an attacker who can forge UDP packets from the configured DNS server trigger a 1-…EPSS 53%analysed7.5CVE-2019-9511HTTP/2 window size and stream priority manipulation denial of serviceMultiple HTTP/2 implementations mishandle window size and stream prioritization, letting an attacker request a large resource across many streams and…EPSS 60%analysed

Source: NIST National Vulnerability Database (record CVE-2014-0088), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.