Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-46872 An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascrip… Nim 1.6.2 / 2.2.0+ Fix from $1,6002023-01-13 HIGH 8.1 CVE-2022-23602 Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an inc… Docutils 1.6.2 / 2.2.0+ Fix from $1,9502022-02-01 MEDIUM 5.5 CVE-2020-23171 A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-… Nim Lang No fix yet Fix from $1,6002021-08-10 HIGH 7.5 CVE-2021-29495 Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification wa… Nim 1.4.2+ Fix from $1,9502021-05-07 HIGH 8.8 CVE-2021-21372 Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in differ… Nim 1.2.10 / 1.4.4+ Fix from $1,9502021-03-26 HIGH 8.1 CVE-2021-21374 Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a li… Nim 1.2.10 / 1.4.4+ Fix from $1,9502021-03-26 MEDIUM 5.9 CVE-2021-21373 Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a li… Nim 1.2.10 / 1.4.4+ Fix from $1,6002021-03-26 CRITICAL 9.8 CVE-2020-15690 In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character. Nim 1.2.6+ Fix from $2,3002021-01-30 CRITICAL 9.8 CVE-2020-15692 In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that w… Nim after 1.2.6 Fix from $2,3002020-08-14 HIGH 7.5 CVE-2020-15694 In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not … Nim after 1.2.6 Fix from $1,9502020-08-14 MEDIUM 6.5 CVE-2020-15693 In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls… Nim after 1.2.6 Fix from $1,6002020-08-14