Nulllogic maintains a focused product portfolio centered on HTTP server and groupware applications, with a niche but persistent vulnerability footprint. The observed weaknesses center on SQL injection and related input-handling issues, reflecting the application-layer parsing demands of web-facing and data-management components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nulllogic over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1496HIGH Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header. | Apr 2, 2003 | 7.5 | 39 | NO | YES |
CVE-2002-1497MEDIUM Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response. | Apr 2, 2003 | 4.3 | 21 | NO | YES |
CVE-2009-2354HIGH SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote attackers to execute arbitrary SQL commands via the username | Jul 7, 2009 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nulllogic.
Media articles that mention a CVE ID that affects a product developed by Nulllogic — matched by CVE ID, not by vendor name.