Vulnerabilities > CVE-2017-14149 - NULL Pointer Dereference vulnerability in Embedthis Goahead

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
embedthis
CWE-476

Summary

GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.

Common Weakness Enumeration (CWE)