Nazgul's vulnerability exposure centers on the Nostromo web server and related HTTP daemon components, a narrowly scoped but historically significant web service platform. The durable signal is path-traversal weakness in its HTTP handling, reflecting the access-control and input-validation demands of a web-facing daemon; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nazgul over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16278CRITICAL Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request. | Oct 14, 2019 | 9.8 | 99 | YES | YES |
CVE-2011-0751HIGH Directory traversal vulnerability in nhttpd (aka Nostromo webserver) before 1.9.4 allows remote attackers to execute arbitrary programs or read arbitrary files via a ..%2f (encoded | Mar 16, 2011 | 7.5 | 35 | NO | YES |
CVE-2019-16279HIGH A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request. | Oct 14, 2019 | 7.5 | 34 | NO | NO |
CVE-2022-48253CRITICAL nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the hom | Jan 11, 2023 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nazgul.
Media articles that mention a CVE ID that affects a product developed by Nazgul — matched by CVE ID, not by vendor name.