Back

CVE-2016-0746

CRITICAL

Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.

Published: Feb 15, 2016 Modified: May 6, 2026
CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (9)

Vendor Product Version
f5 nginx * ≥ 0.6.18
f5 nginx * ≥ 1.9.0 < 1.9.10
canonical ubuntu_linux 14.04
canonical ubuntu_linux 15.10
debian debian_linux 7.0
debian debian_linux 8.0
debian debian_linux 9.0
opensuse leap 42.1
apple xcode * < 13.0

GitHub Security Advisory GHSA-c3r2-x25x-6jwc

Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 6.34%

Top 9% most likely to be exploited

Threat Score 41.1 / 100

Data Sources

NVD EPSS GitHub