EmbedThis records
22 published records for vendor embedthis.
Researcher profile
- Entered KEV
- 1 · 4.5%
- Weaponized
- 2 · 9.1%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- 1459 days
Recurring classes
- CWE-476 NULL Pointer Dereference7
- CWE-17 DEPRECATED: Code1
- CWE-190 Integer Overflow or Wraparound1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-208 Observable Timing Discrepancy1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
91Now | CVE-2017-17562Weaponized | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.embedthis · goahead | High8.1 | KEV | 96.3% | Dec 12, 2017 |
59Plan | CVE-2019-5096Proof of concept | An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server appembedthis · goahead · CWE-416 | Critical9.8 | — | 67.0% | Dec 3, 2019 |
57Plan | CVE-2021-42342Proof of concept | An issue was discovered in GoAhead 4.x and 5.x before 5.1.5.embedthis · goahead · CWE-434 | Critical9.8 | — | 59.5% | Oct 14, 2021 |
45Plan | CVE-2017-5674No exploit | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker embedthis · goahead · CWE-200 | Critical9.8 | — | 21.6% | Mar 13, 2017 |
44Plan | CVE-2019-5097No exploit | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in veembedthis · goahead · CWE-835 | High7.5 | — | 45.1% | Dec 3, 2019 |
42Plan | CVE-2017-1000471No exploit | EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or dembedthis · goahead · CWE-476 | Critical9.8 | — | 8.6% | Jan 3, 2018 |
40Plan | CVE-2021-43298No exploit | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limitingembedthis · goahead · CWE-208 | Critical9.8 | — | 2.3% | Jan 25, 2022 |
39Monitor | CVE-2018-8715Proof of concept | The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.embedthis · appweb · CWE-287 | High8.1 | — | 22.8% | Mar 14, 2018 |
39Monitor | CVE-2021-41615No exploit | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparaembedthis · goahead · CWE-331 | Critical9.8 | — | 1.4% | Aug 8, 2022 |
38Monitor | CVE-2014-9707Weaponized | EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .embedthis · goahead · CWE-17 | High7.5 | — | 28.2% | Mar 31, 2015 |
37Monitor | CVE-2014-9708No exploit | Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Ranembedthis · appweb · CWE-476 | Medium5.0 | — | 56.2% | Mar 31, 2015 |
36Monitor | CVE-2019-16645Proof of concept | An issue was discovered in Embedthis GoAhead 2.5.0.embedthis · goahead · CWE-94 | High8.6 | — | 8.2% | Sep 20, 2019 |
36Monitor | CVE-2020-15688No exploit | The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks.embedthis · goahead · CWE-294 | High8.8 | — | 4.0% | Jul 23, 2020 |
36Monitor | CVE-2017-5675No exploit | A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple whembedthis · goahead · CWE-77 | High8.8 | — | 1.7% | Mar 13, 2017 |
33Monitor | CVE-2019-12822No exploit | In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds meembedthis · goahead · CWE-119 | High7.5 | — | 8.8% | Jun 14, 2019 |
32Monitor | CVE-2017-1000470No exploit | EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of servembedthis · goahead web server · CWE-190 | High7.5 | — | 7.9% | Jan 3, 2018 |
32Monitor | CVE-2017-14149No exploit | GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.embedthis · goahead · CWE-476 | High7.5 | — | 5.8% | Sep 5, 2017 |
31Monitor | CVE-2018-15504No exploit | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.embedthis · appweb · CWE-476 | High7.5 | — | 2.8% | Aug 17, 2018 |
31Monitor | CVE-2018-15505No exploit | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.embedthis · appweb · CWE-476 | High7.5 | — | 2.2% | Aug 17, 2018 |
30Monitor | CVE-2021-33254No exploit | An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service viaembedthis · appweb · CWE-476 | High7.5 | — | 1.5% | Jun 2, 2022 |
30Monitor | CVE-2020-15689No exploit | Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact raembedthis · appweb · CWE-476 | High7.5 | — | 1.3% | Jul 13, 2020 |
21Monitor | CVE-2019-19240No exploit | Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header.embedthis · goahead · CWE-787 | Medium5.3 | — | 1.5% | Nov 22, 2019 |
- CVE-2017-1756291Now
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
HighCVSS 8.1KEVWeaponizedEPSS 96%embedthis · goaheadDec 12, 2017
- CVE-2019-509659Plan
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server app
CriticalCVSS 9.8Proof of conceptEPSS 67%embedthis · goaheadDec 3, 2019
- CVE-2021-4234257Plan
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5.
CriticalCVSS 9.8Proof of conceptEPSS 59%embedthis · goaheadOct 14, 2021
- CVE-2017-567445Plan
A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker
CriticalCVSS 9.8No exploitEPSS 22%embedthis · goaheadMar 13, 2017
- CVE-2019-509744Plan
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in ve
HighCVSS 7.5No exploitEPSS 45%embedthis · goaheadDec 3, 2019
- CVE-2017-100047142Plan
EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or d
CriticalCVSS 9.8No exploitEPSS 9%embedthis · goaheadJan 3, 2018
- CVE-2021-4329840Plan
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting
CriticalCVSS 9.8No exploitEPSS 2%embedthis · goaheadJan 25, 2022
- CVE-2018-871539Monitor
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.
HighCVSS 8.1Proof of conceptEPSS 23%embedthis · appwebMar 14, 2018
- CVE-2021-4161539Monitor
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara
CriticalCVSS 9.8No exploitEPSS 1%embedthis · goaheadAug 8, 2022
- CVE-2014-970738Monitor
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .
HighCVSS 7.5WeaponizedEPSS 28%embedthis · goaheadMar 31, 2015
- CVE-2014-970837Monitor
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Ran
MediumCVSS 5.0No exploitEPSS 56%embedthis · appwebMar 31, 2015
- CVE-2019-1664536Monitor
An issue was discovered in Embedthis GoAhead 2.5.0.
HighCVSS 8.6Proof of conceptEPSS 8%embedthis · goaheadSep 20, 2019
- CVE-2020-1568836Monitor
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks.
HighCVSS 8.8No exploitEPSS 4%embedthis · goaheadJul 23, 2020
- CVE-2017-567536Monitor
A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple wh
HighCVSS 8.8No exploitEPSS 2%embedthis · goaheadMar 13, 2017
- CVE-2019-1282233Monitor
In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds me
HighCVSS 7.5No exploitEPSS 9%embedthis · goaheadJun 14, 2019
- CVE-2017-100047032Monitor
EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of serv
HighCVSS 7.5No exploitEPSS 8%embedthis · goahead web serverJan 3, 2018
- CVE-2017-1414932Monitor
GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.
HighCVSS 7.5No exploitEPSS 6%embedthis · goaheadSep 5, 2017
- CVE-2018-1550431Monitor
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
HighCVSS 7.5No exploitEPSS 3%embedthis · appwebAug 17, 2018
- CVE-2018-1550531Monitor
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
HighCVSS 7.5No exploitEPSS 2%embedthis · appwebAug 17, 2018
- CVE-2021-3325430Monitor
An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via
HighCVSS 7.5No exploitEPSS 2%embedthis · appwebJun 2, 2022
- CVE-2020-1568930Monitor
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact ra
HighCVSS 7.5No exploitEPSS 1%embedthis · appwebJul 13, 2020
- CVE-2019-1924021Monitor
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header.
MediumCVSS 5.3No exploitEPSS 2%embedthis · goaheadNov 22, 2019