Vulnerabilities > Embedthis

DATE CVE VULNERABILITY TITLE RISK
2019-06-14 CVE-2019-12822 Expression Language Injection vulnerability in Embedthis Goahead
In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and potential DoS, as demonstrated by a colon on a line by itself.
network
low complexity
embedthis CWE-917
7.5
2018-08-18 CVE-2018-15505 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
network
low complexity
embedthis juniper CWE-476
7.5
2018-08-18 CVE-2018-15504 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
network
low complexity
embedthis juniper CWE-476
7.5
2018-03-15 CVE-2018-8715 Improper Authentication vulnerability in Embedthis Appweb
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.
network
high complexity
embedthis CWE-287
8.1
2018-01-03 CVE-2017-1000471 NULL Pointer Dereference vulnerability in Embedthis Goahead 4.0.0
EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.
network
low complexity
embedthis CWE-476
critical
9.8
2018-01-03 CVE-2017-1000470 Integer Overflow or Wraparound vulnerability in Embedthis Goahead web Server 4.0.0
EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.
network
low complexity
embedthis CWE-190
7.5
2017-12-12 CVE-2017-17562 Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
network
high complexity
embedthis oracle
8.1
2017-09-05 CVE-2017-14149 NULL Pointer Dereference vulnerability in Embedthis Goahead
GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.
network
low complexity
embedthis CWE-476
7.5
2017-03-13 CVE-2017-5675 Command Injection vulnerability in Embedthis Goahead
A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models.
network
low complexity
embedthis CWE-77
8.8
2017-03-13 CVE-2017-5674 Information Exposure vulnerability in Embedthis Goahead
A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password.
network
low complexity
embedthis CWE-200
critical
9.8