Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sp0Re

#15625of 53,622
17.3Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2019-14609
9.8
2019-10-14
Nostromo · Nostromo Nhttpd · CVE-2019-16278
**Name of the Vulnerable Software and Affected Versions** Nostromo nhttpd versions 1.9.6 and earlier **Description** The issue allows an attacker to achieve remote code execution via a crafted HTTP request due to a directory traversal vulnerability in the `http verify` function. This vulnerability is being actively exploited. **Recommendations** For versions 1.9.6 and earlier, update to a version that fixes the directory traversal vulnerability in the `http verify` function to prevent remote code execution. As a temporary workaround, consider restricting access to the `http verify` function until a patch is available.
PT-2019-14610
7.5
2019-10-14
Nostromo · Nostromo Nhttpd · CVE-2019-16279
**Name of the Vulnerable Software and Affected Versions** nostromo nhttpd versions 1.9.6 and earlier **Description** A memory error in the `SSL accept` function allows an attacker to trigger a denial of service via a crafted HTTP request. **Recommendations** For versions 1.9.6 and earlier, consider disabling the `SSL accept` function as a temporary workaround until a patch is available.