Nim
Vendor:
First CVE: Aug 14, 2020 · Active for 5 years
9
Total CVEs
More Total CVEs than 88% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 66% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nim over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2020
5 years ago
Most Recent CVE
Jan 13, 2023
1,292 days ago
CVE Severity & Scoring
Nim9 CVEs
33%
44%
22%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High2 (22.2%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15692CRITICAL In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default ex | Aug 14, 2020 | 9.8 | 32 | NO | NO |
CVE-2021-21372HIGH Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged | Mar 26, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-21374HIGH Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTP | Mar 26, 2021 | 8.1 | 25 | NO | NO |
CVE-2020-15690CRITICAL In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character. | Jan 30, 2021 | 9.8 | 25 | NO | NO |
CVE-2021-29495HIGH Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification was disabled by default. Users ca | May 7, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-46872MEDIUM An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead | Jan 13, 2023 | 6.1 | 21 | NO | NO |
CVE-2021-21373MEDIUM Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTP | Mar 26, 2021 | 5.9 | 20 | NO | NO |
CVE-2020-15694HIGH In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious | Aug 14, 2020 | 7.5 | 20 | NO | NO |
CVE-2020-15693MEDIUM In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided i | Aug 14, 2020 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Nim
Top CWEs
Versions
No cataloged versions.