CVE-2014-9708

Severity
5.0MEDIUM
EPSS
4.5%
top 10.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 14

Description

Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDembedthis/appweb5.0.05.2.1+1
NVDjuniper/junos16 versions+15

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3r9x-rvv2-cq7m: Embedthis Appweb before 42022-05-14
CVEList
CVE-2014-9708: Embedthis Appweb before 42015-03-31
CVE-2014-9708 (MEDIUM CVSS 5) | Embedthis Appweb before 4.6.6 and 5 | cvebase.io