Skip to content
Noroxi

EmbedThis records

22 published records for vendor embedthis.

Researcher profile

Entered KEV
1 · 4.5%
Weaponized
2 · 9.1%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
1459 days

All records

22 records
  • Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.

    HighCVSS 8.1KEVWeaponizedEPSS 96%

    embedthis · goaheadDec 12, 2017

  • An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server app

    CriticalCVSS 9.8Proof of conceptEPSS 67%

    embedthis · goaheadDec 3, 2019

  • An issue was discovered in GoAhead 4.x and 5.x before 5.1.5.

    CriticalCVSS 9.8Proof of conceptEPSS 59%

    embedthis · goaheadOct 14, 2021

  • A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker

    CriticalCVSS 9.8No exploitEPSS 22%

    embedthis · goaheadMar 13, 2017

  • A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in ve

    HighCVSS 7.5No exploitEPSS 45%

    embedthis · goaheadDec 3, 2019

  • EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or d

    CriticalCVSS 9.8No exploitEPSS 9%

    embedthis · goaheadJan 3, 2018

  • The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting

    CriticalCVSS 9.8No exploitEPSS 2%

    embedthis · goaheadJan 25, 2022

  • CVE-2018-8715
    39Monitor

    The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.

    HighCVSS 8.1Proof of conceptEPSS 23%

    embedthis · appwebMar 14, 2018

  • websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara

    CriticalCVSS 9.8No exploitEPSS 1%

    embedthis · goaheadAug 8, 2022

  • CVE-2014-9707
    38Monitor

    EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .

    HighCVSS 7.5WeaponizedEPSS 28%

    embedthis · goaheadMar 31, 2015

  • CVE-2014-9708
    37Monitor

    Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Ran

    MediumCVSS 5.0No exploitEPSS 56%

    embedthis · appwebMar 31, 2015

  • An issue was discovered in Embedthis GoAhead 2.5.0.

    HighCVSS 8.6Proof of conceptEPSS 8%

    embedthis · goaheadSep 20, 2019

  • The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks.

    HighCVSS 8.8No exploitEPSS 4%

    embedthis · goaheadJul 23, 2020

  • CVE-2017-5675
    36Monitor

    A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple wh

    HighCVSS 8.8No exploitEPSS 2%

    embedthis · goaheadMar 13, 2017

  • In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds me

    HighCVSS 7.5No exploitEPSS 9%

    embedthis · goaheadJun 14, 2019

  • EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of serv

    HighCVSS 7.5No exploitEPSS 8%

    embedthis · goahead web serverJan 3, 2018

  • GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.

    HighCVSS 7.5No exploitEPSS 6%

    embedthis · goaheadSep 5, 2017

  • An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.

    HighCVSS 7.5No exploitEPSS 3%

    embedthis · appwebAug 17, 2018

  • An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.

    HighCVSS 7.5No exploitEPSS 2%

    embedthis · appwebAug 17, 2018

  • An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via

    HighCVSS 7.5No exploitEPSS 2%

    embedthis · appwebJun 2, 2022

  • Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact ra

    HighCVSS 7.5No exploitEPSS 1%

    embedthis · appwebJul 13, 2020

  • Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header.

    MediumCVSS 5.3No exploitEPSS 2%

    embedthis · goaheadNov 22, 2019