Nathan Neulinger's vulnerability footprint centers on cgiwrap, a CGI wrapper utility for web servers that enforces privilege separation and resource limits on dynamically executed scripts. The observed weakness classes reflect the product's role in web request handling, with documented issues in input validation and cross-site scripting prevention that are characteristic of CGI-layer software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nathan Neulinger over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0987HIGH Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into | Jul 22, 2001 | 7.5 | 31 | NO | YES |
CVE-2005-3254HIGH The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attac | Oct 18, 2005 | 10.0 | 25 | NO | NO |
CVE-2006-0767MEDIUM CGIWrap before 3.10 allows remote attackers to obtain sensitive information via unknown attack vectors that cause errors in scripts that reveal system information. | Feb 18, 2006 | 5.0 | 15 | NO | NO |
CVE-2005-3255MEDIUM The (1) cgiwrap and (2) php-cgiwrap packages before 3.9 in Debian GNU/Linux provide access to debugging CGIs under the web document root, which allows remote attackers to obtain se | Oct 18, 2005 | 5.0 | 15 | NO | NO |
CVE-2008-2852MEDIUM Cross-site scripting (XSS) vulnerability in CGIWrap before 4.1, when an Internet Explorer based browser is used, allows remote attackers to inject arbitrary web script or HTML via | Jun 25, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nathan Neulinger.
Media articles that mention a CVE ID that affects a product developed by Nathan Neulinger — matched by CVE ID, not by vendor name.