VYPR

nhttpd

by Nostromo

CVEs (3)

  • CVE-2019-16278CriKEVOct 14, 2019
    risk 0.87cvss 9.8epss 0.99

    Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.

  • CVE-2022-48253CriJan 11, 2023
    risk 0.64cvss 9.8epss 0.03

    nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used.

  • CVE-2019-16279HigOct 14, 2019
    risk 0.50cvss 7.5epss 0.20

    A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.