Skip to main content

Vendor/product archive

embedthis / appweb CVEs

Beta · best-effort

6 CVEs tagged to embedthis / appweb0 Critical, 5 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2021-33254

Published Jun 2, 2022

An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri fu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15689

Published Jul 13, 2020

Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8715

Published Mar 15, 2018

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1