CVE-2017-7529
HIGH 7.5EPSS 62.6%
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 62.60% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- medium
- Published
- 2017-07-13
- Updated
- 2024-09-16
Proof-of-concept exploits (23)
- AMEENVKD/Nginx1.10.2Checker0★ · 2023-06-16
- Fenil2511/CVE-2017-7529-POC0★ · 2025-03-05
- MAD-Goat-Project/mad-goat-docs0★ · 2026-05-21
- MaxSecurity/CVE-2017-7529-POC4★ · 2019-06-06
- Shehzadcyber/CVE-2017-752911★ · 2022-07-18
- SirEagIe/CVE-2017-75290★ · 2024-04-25
- coolman6942o/-Exploit-CVE-2017-75291★ · 2023-12-19
- cved-sources/cve-2017-75290★ · 2021-04-15
- cyberharsh/nginx-CVE-2017-75292★ · 2020-07-02
- cyberk1w1/CVE-2017-75290★ · 2020-06-18
- en0f/CVE-2017-7529_PoC19★ · 2026-01-07
- fazalur076/POC0★ · 2022-07-20
- fazalurrahman076/POC0★ · 2022-07-20
- fu2x2000/CVE-2017-7529-Nginx---Remote-Integer-Overflow-Exploit0★ · 2021-09-01
- gemboxteam/exploit-nginx-1.10.312★ · 2021-01-19
- liusec/CVE-2017-752916★ · 2017-07-21
- merlinepedra/nginxpwner1★ · 2023-03-25
- nicdelhi/CVE-POC0★ · 2020-09-14
- ninjabuster/exploit-nginx-1.10.312★ · 2021-01-19
- portfolio10/nginx0★ · 2025-04-27
- stark0de/nginxpwner1599★ · 2024-03-04
- y1ng1996/w8scan8★ · 2017-09-15
- youngmin0104/CVE-2017-7529-0★ · 2025-04-17