EmbedThis kayıtları
embedthis üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %4,5
- Silahlaştırılmış
- 2 · %9,1
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 1459 gün
Tekrar eden sınıflar
- CWE-476 NULL Pointer Dereference7
- CWE-17 DEPRECATED: Code1
- CWE-190 Integer Overflow or Wraparound1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-208 Observable Timing Discrepancy1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2017-17562Silahlaştırılmış | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.embedthis · goahead | Yüksek8,1 | KEV | %96,3 | 12 Ara 2017 |
59Planlayın | CVE-2019-5096Kavram kanıtı | An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server appembedthis · goahead · CWE-416 | Kritik9,8 | — | %67,0 | 3 Ara 2019 |
57Planlayın | CVE-2021-42342Kavram kanıtı | An issue was discovered in GoAhead 4.x and 5.x before 5.1.5.embedthis · goahead · CWE-434 | Kritik9,8 | — | %59,5 | 14 Eki 2021 |
45Planlayın | CVE-2017-5674İstismar yok | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker embedthis · goahead · CWE-200 | Kritik9,8 | — | %21,6 | 13 Mar 2017 |
44Planlayın | CVE-2019-5097İstismar yok | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in veembedthis · goahead · CWE-835 | Yüksek7,5 | — | %45,1 | 3 Ara 2019 |
42Planlayın | CVE-2017-1000471İstismar yok | EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or dembedthis · goahead · CWE-476 | Kritik9,8 | — | %8,6 | 3 Oca 2018 |
40Planlayın | CVE-2021-43298İstismar yok | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limitingembedthis · goahead · CWE-208 | Kritik9,8 | — | %2,3 | 25 Oca 2022 |
39İzleyin | CVE-2018-8715Kavram kanıtı | The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.embedthis · appweb · CWE-287 | Yüksek8,1 | — | %22,8 | 14 Mar 2018 |
39İzleyin | CVE-2021-41615İstismar yok | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparaembedthis · goahead · CWE-331 | Kritik9,8 | — | %1,4 | 8 Ağu 2022 |
38İzleyin | CVE-2014-9707Silahlaştırılmış | EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .embedthis · goahead · CWE-17 | Yüksek7,5 | — | %28,2 | 31 Mar 2015 |
37İzleyin | CVE-2014-9708İstismar yok | Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Ranembedthis · appweb · CWE-476 | Orta5,0 | — | %56,2 | 31 Mar 2015 |
36İzleyin | CVE-2019-16645Kavram kanıtı | An issue was discovered in Embedthis GoAhead 2.5.0.embedthis · goahead · CWE-94 | Yüksek8,6 | — | %8,2 | 20 Eyl 2019 |
36İzleyin | CVE-2020-15688İstismar yok | The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks.embedthis · goahead · CWE-294 | Yüksek8,8 | — | %4,0 | 23 Tem 2020 |
36İzleyin | CVE-2017-5675İstismar yok | A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple whembedthis · goahead · CWE-77 | Yüksek8,8 | — | %1,7 | 13 Mar 2017 |
33İzleyin | CVE-2019-12822İstismar yok | In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds meembedthis · goahead · CWE-119 | Yüksek7,5 | — | %8,8 | 14 Haz 2019 |
32İzleyin | CVE-2017-1000470İstismar yok | EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of servembedthis · goahead web server · CWE-190 | Yüksek7,5 | — | %7,9 | 3 Oca 2018 |
32İzleyin | CVE-2017-14149İstismar yok | GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.embedthis · goahead · CWE-476 | Yüksek7,5 | — | %5,8 | 5 Eyl 2017 |
31İzleyin | CVE-2018-15504İstismar yok | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.embedthis · appweb · CWE-476 | Yüksek7,5 | — | %2,8 | 17 Ağu 2018 |
31İzleyin | CVE-2018-15505İstismar yok | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.embedthis · appweb · CWE-476 | Yüksek7,5 | — | %2,2 | 17 Ağu 2018 |
30İzleyin | CVE-2021-33254İstismar yok | An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service viaembedthis · appweb · CWE-476 | Yüksek7,5 | — | %1,5 | 2 Haz 2022 |
30İzleyin | CVE-2020-15689İstismar yok | Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact raembedthis · appweb · CWE-476 | Yüksek7,5 | — | %1,3 | 13 Tem 2020 |
21İzleyin | CVE-2019-19240İstismar yok | Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header.embedthis · goahead · CWE-787 | Orta5,3 | — | %1,5 | 22 Kas 2019 |
- CVE-2017-1756291Hemen
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %96embedthis · goahead12 Ara 2017
- CVE-2019-509659Planlayın
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server app
KritikCVSS 9,8Kavram kanıtıEPSS %67embedthis · goahead3 Ara 2019
- CVE-2021-4234257Planlayın
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5.
KritikCVSS 9,8Kavram kanıtıEPSS %59embedthis · goahead14 Eki 2021
- CVE-2017-567445Planlayın
A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker
KritikCVSS 9,8İstismar yokEPSS %22embedthis · goahead13 Mar 2017
- CVE-2019-509744Planlayın
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in ve
YüksekCVSS 7,5İstismar yokEPSS %45embedthis · goahead3 Ara 2019
- CVE-2017-100047142Planlayın
EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or d
KritikCVSS 9,8İstismar yokEPSS %9embedthis · goahead3 Oca 2018
- CVE-2021-4329840Planlayın
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting
KritikCVSS 9,8İstismar yokEPSS %2embedthis · goahead25 Oca 2022
- CVE-2018-871539İzleyin
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.
YüksekCVSS 8,1Kavram kanıtıEPSS %23embedthis · appweb14 Mar 2018
- CVE-2021-4161539İzleyin
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara
KritikCVSS 9,8İstismar yokEPSS %1embedthis · goahead8 Ağu 2022
- CVE-2014-970738İzleyin
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .
YüksekCVSS 7,5SilahlaştırılmışEPSS %28embedthis · goahead31 Mar 2015
- CVE-2014-970837İzleyin
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Ran
OrtaCVSS 5,0İstismar yokEPSS %56embedthis · appweb31 Mar 2015
- CVE-2019-1664536İzleyin
An issue was discovered in Embedthis GoAhead 2.5.0.
YüksekCVSS 8,6Kavram kanıtıEPSS %8embedthis · goahead20 Eyl 2019
- CVE-2020-1568836İzleyin
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks.
YüksekCVSS 8,8İstismar yokEPSS %4embedthis · goahead23 Tem 2020
- CVE-2017-567536İzleyin
A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple wh
YüksekCVSS 8,8İstismar yokEPSS %2embedthis · goahead13 Mar 2017
- CVE-2019-1282233İzleyin
In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds me
YüksekCVSS 7,5İstismar yokEPSS %9embedthis · goahead14 Haz 2019
- CVE-2017-100047032İzleyin
EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of serv
YüksekCVSS 7,5İstismar yokEPSS %8embedthis · goahead web server3 Oca 2018
- CVE-2017-1414932İzleyin
GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.
YüksekCVSS 7,5İstismar yokEPSS %6embedthis · goahead5 Eyl 2017
- CVE-2018-1550431İzleyin
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
YüksekCVSS 7,5İstismar yokEPSS %3embedthis · appweb17 Ağu 2018
- CVE-2018-1550531İzleyin
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
YüksekCVSS 7,5İstismar yokEPSS %2embedthis · appweb17 Ağu 2018
- CVE-2021-3325430İzleyin
An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via
YüksekCVSS 7,5İstismar yokEPSS %2embedthis · appweb2 Haz 2022
- CVE-2020-1568930İzleyin
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact ra
YüksekCVSS 7,5İstismar yokEPSS %1embedthis · appweb13 Tem 2020
- CVE-2019-1924021İzleyin
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header.
OrtaCVSS 5,3İstismar yokEPSS %2embedthis · goahead22 Kas 2019