Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nim MEDIUM 6.1
CVE-2021-46872

An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascrip…

Fix: 1.6.2 / 2.2.0+
Fix from $1,600 2023-01-13
Docutils HIGH 8.1
CVE-2022-23602

Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an inc…

Fix: 1.6.2 / 2.2.0+
Fix from $1,950 2022-02-01
Nim Lang MEDIUM 5.5
CVE-2020-23171

A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-…

No fix yet
Fix from $1,600 2021-08-10
Nim HIGH 7.5
CVE-2021-29495

Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification wa…

Fix: 1.4.2+
Fix from $1,950 2021-05-07
Nim HIGH 8.8
CVE-2021-21372

Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in differ…

Fix: 1.2.10 / 1.4.4+
Fix from $1,950 2021-03-26
Nim HIGH 8.1
CVE-2021-21374

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a li…

Fix: 1.2.10 / 1.4.4+
Fix from $1,950 2021-03-26
Nim MEDIUM 5.9
CVE-2021-21373

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a li…

Fix: 1.2.10 / 1.4.4+
Fix from $1,600 2021-03-26
Nim CRITICAL 9.8
CVE-2020-15690

In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.

Fix: 1.2.6+
Fix from $2,300 2021-01-30
Nim CRITICAL 9.8
CVE-2020-15692

In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that w…

Fix: after 1.2.6
Fix from $2,300 2020-08-14
Nim HIGH 7.5
CVE-2020-15694

In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not …

Fix: after 1.2.6
Fix from $1,950 2020-08-14
Nim MEDIUM 6.5
CVE-2020-15693

In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls…

Fix: after 1.2.6
Fix from $1,600 2020-08-14