A heap overflow in BIG-IP APM hands unauthenticated attackers code execution on any appliance serving as an OAuth authorization server.
F5 patched a critical Nginx heap buffer overflow that lets unauthenticated attackers crash workers or achieve remote code execution.
An 18 year old heap buffer overflow in NGINX's rewrite module allows unauthenticated remote code execution through crafted HTTP requests.