Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

nullsoft

About This Vendor

nullsoft is a technology vendor producing software and infrastructure products. As a software provider, nullsoft's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of nullsoft's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 76 known vulnerabilities from nullsoft. This includes 51 high-severity issues requiring prompt remediation. These vulnerabilities affect 9 distinct products across nullsoft's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 1999 through 2023, indicating decades of continuous security attention and research. Organizations deploying nullsoft products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-1999-1561 1999-08-20 2025-04-03 - 7.2 Unknown
CVE-2000-0049 2000-01-04 2025-04-03 - 7.2 Unknown
CVE-2000-0624 2000-07-20 2025-04-03 - 7.5 Likely
CVE-2001-0490 2001-06-27 2025-04-03 - 7.5 Likely
CVE-2001-1304 2001-08-03 2025-04-03 - 5.0 Likely
CVE-2002-0199 2002-05-16 2025-04-03 - 7.5 Likely
CVE-2002-0284 2002-05-31 2025-04-03 - 2.6 Unknown
CVE-2002-0546 2002-07-03 2025-04-03 - 7.5 Likely
CVE-2002-0547 2002-07-03 2025-04-03 - 7.5 Likely
CVE-2002-0907 2002-10-04 2025-04-03 - 7.5 Likely
CVE-2002-1176 2002-12-26 2025-04-03 - 7.5 Likely
CVE-2002-1177 2002-12-26 2025-04-03 - 7.5 Likely
CVE-2002-2195 2002-12-31 2025-04-03 - 5.0 Likely
CVE-2002-2392 2002-12-31 2025-04-03 - 6.4 Likely
CVE-2002-2412 2002-12-31 2025-04-03 - 2.1 Unknown
CVE-2002-1524 2003-04-02 2025-04-03 - 7.5 Likely
CVE-2002-1470 2003-04-22 2025-04-03 - 2.1 Unknown
CVE-2003-0765 2003-09-17 2025-04-03 - 7.5 Likely
CVE-2003-1174 2003-12-31 2025-04-03 - 2.1 Unknown
CVE-2003-1272 2003-12-31 2025-04-03 - 9.3 Likely
CVE-2003-1273 2003-12-31 2025-04-03 - 2.1 Unknown
CVE-2003-1274 2003-12-31 2025-04-03 - 5.0 Likely
CVE-2004-0820 2004-08-28 2025-04-03 - 4.6 Unknown
CVE-2004-1373 2004-12-23 2025-04-03 - 7.5 Likely
CVE-2004-1150 2004-12-31 2025-04-03 - 5.1 Unknown
CVE-2004-1396 2004-12-31 2025-04-03 - 2.6 Unknown
CVE-2004-1896 2004-12-31 2025-04-03 - 7.6 Unknown
CVE-2004-2384 2004-12-31 2025-04-03 - 5.0 Likely
CVE-2004-1119 2005-01-10 2025-04-03 - 10.0 Likely
CVE-2005-2310 2005-07-19 2025-04-03 - 9.3 Likely
CVE-2005-3188 2005-12-31 2025-04-03 - 7.6 Unknown
CVE-2006-0476 2006-01-31 2025-04-03 - 7.6 Unknown
CVE-2006-0708 2006-02-15 2025-04-03 - 9.3 Likely
CVE-2006-0720 2006-02-23 2025-04-03 - 7.6 Unknown
CVE-2006-3007 2006-06-13 2025-04-03 - 4.3 Likely
CVE-2006-3228 2006-06-26 2025-04-03 - 9.3 Likely
CVE-2006-3534 2006-07-12 2025-04-03 - 7.8 Likely
CVE-2006-3535 2006-07-12 2025-04-03 - 5.0 Likely
CVE-2006-5567 2006-10-27 2025-04-09 - 9.3 Likely
CVE-2007-1229 2007-03-02 2025-04-09 - 4.3 Likely
CVE-2007-1921 2007-04-10 2025-04-09 - 9.3 Likely
CVE-2007-1922 2007-04-10 2025-04-09 - 9.3 Likely
CVE-2007-2180 2007-04-24 2025-04-09 - 7.1 Likely
CVE-2007-2498 2007-05-04 2025-04-09 - 9.3 Likely
CVE-2007-4392 2007-08-17 2025-04-09 - 4.3 Likely
CVE-2007-4619 2007-10-12 2025-04-09 - 9.3 Likely
CVE-2008-3441 2008-08-01 2025-04-09 - 7.5 Likely
CVE-2008-3567 2008-08-10 2025-04-09 - 4.3 Likely
CVE-2009-0263 2009-01-23 2025-04-09 - 10.0 Likely
CVE-2009-0186 2009-03-05 2025-04-09 - 9.3 Likely
CVE-2009-0833 2009-03-05 2025-04-09 - 9.3 Likely
CVE-2009-1788 2009-05-26 2025-04-09 - 9.3 Likely
CVE-2009-1791 2009-05-26 2025-04-09 - 9.3 Likely
CVE-2009-1831 2009-05-29 2025-04-09 - 9.3 Likely
CVE-2009-3995 2009-12-18 2025-04-09 - 9.3 Likely
CVE-2009-3997 2009-12-18 2025-04-09 - 9.3 Likely
CVE-2009-3996 2009-12-18 2025-04-09 - 9.3 Likely
CVE-2009-4356 2009-12-18 2025-04-09 - 9.3 Likely
CVE-2010-3137 2010-08-26 2025-04-11 - 9.3 Likely
CVE-2010-1523 2010-11-06 2025-04-11 - 9.3 Likely
CVE-2010-2586 2010-12-02 2025-04-11 - 9.3 Likely
CVE-2010-4370 2010-12-02 2025-04-11 - 9.3 Likely
CVE-2010-4371 2010-12-02 2025-04-11 - 9.3 Likely
CVE-2010-4372 2010-12-02 2025-04-11 - 9.3 Likely
CVE-2010-4373 2010-12-02 2025-04-11 - 4.3 Likely
CVE-2010-4374 2010-12-02 2025-04-11 - 4.3 Likely
CVE-2011-3834 2011-12-16 2025-04-11 - 9.3 Likely
CVE-2011-4857 2011-12-16 2025-04-11 - 10.0 Likely
CVE-2012-3889 2012-07-11 2025-04-11 - 6.8 Likely
CVE-2012-3890 2012-07-11 2025-04-11 - 6.8 Likely
CVE-2012-4045 2012-07-22 2025-04-11 - 7.5 Likely
CVE-2013-4694 2014-04-16 2025-04-12 - 7.5 Likely
CVE-2014-3442 2014-05-23 2025-04-12 - 4.3 Likely
CVE-2015-9267 2018-10-01 2024-11-21 5.5 3.6 Unknown
CVE-2015-9268 2018-10-01 2024-11-21 7.8 9.3 Likely
CVE-2023-37378 2023-07-03 2024-11-21 5.3 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for nullsoft by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with nullsoft's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.