Записи EmbedThis
22 опубликованных записей вендора embedthis.
Профиль для исследователя
- Попали в KEV
- 1 · 4,5 %
- С эксплойтом
- 2 · 9,1 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 1459 дн.
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference7
- CWE-17 DEPRECATED: Code1
- CWE-190 Integer Overflow or Wraparound1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-208 Observable Timing Discrepancy1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
91Срочно | CVE-2017-17562Готовый эксплойт | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.embedthis · goahead | Высокая8,1 | KEV | 96,3 % | 12 дек. 2017 г. |
59В плане | CVE-2019-5096Proof of concept | An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server appembedthis · goahead · CWE-416 | Критическая9,8 | — | 67,0 % | 3 дек. 2019 г. |
57В плане | CVE-2021-42342Proof of concept | An issue was discovered in GoAhead 4.x and 5.x before 5.1.5.embedthis · goahead · CWE-434 | Критическая9,8 | — | 59,5 % | 14 окт. 2021 г. |
45В плане | CVE-2017-5674Эксплойта нет | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker embedthis · goahead · CWE-200 | Критическая9,8 | — | 21,6 % | 13 мар. 2017 г. |
44В плане | CVE-2019-5097Эксплойта нет | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in veembedthis · goahead · CWE-835 | Высокая7,5 | — | 45,1 % | 3 дек. 2019 г. |
42В плане | CVE-2017-1000471Эксплойта нет | EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or dembedthis · goahead · CWE-476 | Критическая9,8 | — | 8,6 % | 3 янв. 2018 г. |
40В плане | CVE-2021-43298Эксплойта нет | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limitingembedthis · goahead · CWE-208 | Критическая9,8 | — | 2,3 % | 25 янв. 2022 г. |
39Наблюдать | CVE-2018-8715Proof of concept | The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.embedthis · appweb · CWE-287 | Высокая8,1 | — | 22,8 % | 14 мар. 2018 г. |
39Наблюдать | CVE-2021-41615Эксплойта нет | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparaembedthis · goahead · CWE-331 | Критическая9,8 | — | 1,4 % | 8 авг. 2022 г. |
38Наблюдать | CVE-2014-9707Готовый эксплойт | EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .embedthis · goahead · CWE-17 | Высокая7,5 | — | 28,2 % | 31 мар. 2015 г. |
37Наблюдать | CVE-2014-9708Эксплойта нет | Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Ranembedthis · appweb · CWE-476 | Средняя5,0 | — | 56,2 % | 31 мар. 2015 г. |
36Наблюдать | CVE-2019-16645Proof of concept | An issue was discovered in Embedthis GoAhead 2.5.0.embedthis · goahead · CWE-94 | Высокая8,6 | — | 8,2 % | 20 сент. 2019 г. |
36Наблюдать | CVE-2020-15688Эксплойта нет | The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks.embedthis · goahead · CWE-294 | Высокая8,8 | — | 4,0 % | 23 июл. 2020 г. |
36Наблюдать | CVE-2017-5675Эксплойта нет | A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple whembedthis · goahead · CWE-77 | Высокая8,8 | — | 1,7 % | 13 мар. 2017 г. |
33Наблюдать | CVE-2019-12822Эксплойта нет | In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds meembedthis · goahead · CWE-119 | Высокая7,5 | — | 8,8 % | 14 июн. 2019 г. |
32Наблюдать | CVE-2017-1000470Эксплойта нет | EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of servembedthis · goahead web server · CWE-190 | Высокая7,5 | — | 7,9 % | 3 янв. 2018 г. |
32Наблюдать | CVE-2017-14149Эксплойта нет | GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.embedthis · goahead · CWE-476 | Высокая7,5 | — | 5,8 % | 5 сент. 2017 г. |
31Наблюдать | CVE-2018-15504Эксплойта нет | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.embedthis · appweb · CWE-476 | Высокая7,5 | — | 2,8 % | 17 авг. 2018 г. |
31Наблюдать | CVE-2018-15505Эксплойта нет | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.embedthis · appweb · CWE-476 | Высокая7,5 | — | 2,2 % | 17 авг. 2018 г. |
30Наблюдать | CVE-2021-33254Эксплойта нет | An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service viaembedthis · appweb · CWE-476 | Высокая7,5 | — | 1,5 % | 2 июн. 2022 г. |
30Наблюдать | CVE-2020-15689Эксплойта нет | Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact raembedthis · appweb · CWE-476 | Высокая7,5 | — | 1,3 % | 13 июл. 2020 г. |
21Наблюдать | CVE-2019-19240Эксплойта нет | Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header.embedthis · goahead · CWE-787 | Средняя5,3 | — | 1,5 % | 22 нояб. 2019 г. |
- CVE-2017-1756291Срочно
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 96 %embedthis · goahead12 дек. 2017 г.
- CVE-2019-509659В плане
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server app
КритическаяCVSS 9,8Proof of conceptEPSS 67 %embedthis · goahead3 дек. 2019 г.
- CVE-2021-4234257В плане
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5.
КритическаяCVSS 9,8Proof of conceptEPSS 59 %embedthis · goahead14 окт. 2021 г.
- CVE-2017-567445В плане
A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker
КритическаяCVSS 9,8Эксплойта нетEPSS 22 %embedthis · goahead13 мар. 2017 г.
- CVE-2019-509744В плане
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in ve
ВысокаяCVSS 7,5Эксплойта нетEPSS 45 %embedthis · goahead3 дек. 2019 г.
- CVE-2017-100047142В плане
EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or d
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %embedthis · goahead3 янв. 2018 г.
- CVE-2021-4329840В плане
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %embedthis · goahead25 янв. 2022 г.
- CVE-2018-871539Наблюдать
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.
ВысокаяCVSS 8,1Proof of conceptEPSS 23 %embedthis · appweb14 мар. 2018 г.
- CVE-2021-4161539Наблюдать
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %embedthis · goahead8 авг. 2022 г.
- CVE-2014-970738Наблюдать
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .
ВысокаяCVSS 7,5Готовый эксплойтEPSS 28 %embedthis · goahead31 мар. 2015 г.
- CVE-2014-970837Наблюдать
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Ran
СредняяCVSS 5,0Эксплойта нетEPSS 56 %embedthis · appweb31 мар. 2015 г.
- CVE-2019-1664536Наблюдать
An issue was discovered in Embedthis GoAhead 2.5.0.
ВысокаяCVSS 8,6Proof of conceptEPSS 8 %embedthis · goahead20 сент. 2019 г.
- CVE-2020-1568836Наблюдать
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %embedthis · goahead23 июл. 2020 г.
- CVE-2017-567536Наблюдать
A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple wh
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %embedthis · goahead13 мар. 2017 г.
- CVE-2019-1282233Наблюдать
In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds me
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %embedthis · goahead14 июн. 2019 г.
- CVE-2017-100047032Наблюдать
EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of serv
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %embedthis · goahead web server3 янв. 2018 г.
- CVE-2017-1414932Наблюдать
GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %embedthis · goahead5 сент. 2017 г.
- CVE-2018-1550431Наблюдать
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %embedthis · appweb17 авг. 2018 г.
- CVE-2018-1550531Наблюдать
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %embedthis · appweb17 авг. 2018 г.
- CVE-2021-3325430Наблюдать
An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %embedthis · appweb2 июн. 2022 г.
- CVE-2020-1568930Наблюдать
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact ra
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %embedthis · appweb13 июл. 2020 г.
- CVE-2019-1924021Наблюдать
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header.
СредняяCVSS 5,3Эксплойта нетEPSS 2 %embedthis · goahead22 нояб. 2019 г.