Skip to main content

Vendor archive

embedthis CVEs

Beta · best-effort

22 CVEs tagged to vendor embedthis6 Critical, 14 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2021-41615

Published Aug 8, 2022

websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which does not follow the s…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-33254

Published Jun 2, 2022

An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri fu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43298

Published Jan 25, 2022

The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated ne…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-42342

Published Oct 14, 2021

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15688

Published Jul 23, 2020

The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15689

Published Jul 13, 2020

Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5097

Published Dec 3, 2019

A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A sp…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-5096

Published Dec 3, 2019

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 an…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-19240

Published Nov 22, 2019

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can o…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16645

Published Sep 20, 2019

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12822

Published Jun 14, 2019

In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and potential DoS, as d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8715

Published Mar 15, 2018

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000471

Published Jan 3, 2018

EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000470

Published Jan 3, 2018

EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17562

Published Dec 12, 2017

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked C…

CVSS 8.1 · High
evidence mentions
4
Buzz score
47.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-14149

Published Sep 5, 2017

GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5675

Published Mar 13, 2017

A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models. The mail-se…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5674

Published Mar 13, 2017

A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2014-9707

Published Mar 31, 2015

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1