Embedthis Appweb vulnerabilities
6 known vulnerabilities affecting embedthis/appweb.
Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-33254HIGHCVSS 7.5v8.2.12022-06-02
CVE-2021-33254 [HIGH] CWE-476 CVE-2021-33254: An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows at
An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.
nvd
CVE-2020-15689HIGHCVSS 7.5fixed in 7.2.2≥ 8.0.0, < 8.1.02020-07-13
CVE-2020-15689 [HIGH] CWE-476 CVE-2020-15689: Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request wi
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.
nvd
CVE-2018-15504HIGHCVSS 7.5fixed in 7.0.22018-08-18
CVE-2018-15504 [HIGH] CWE-476 CVE-2018-15504: An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishan
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
nvd
CVE-2018-15505HIGHCVSS 7.5fixed in 7.0.22018-08-18
CVE-2018-15505 [HIGH] CWE-476 CVE-2018-15505: An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST requ
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
nvd
CVE-2018-8715HIGHCVSS 8.1PoC≤ 7.0.22018-03-15
CVE-2018-8715 [HIGH] CWE-287 CVE-2018-8715: The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authC
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
nvd
CVE-2014-9708MEDIUMCVSS 5.0fixed in 4.6.6≥ 5.0.0, < 5.2.12015-03-31
CVE-2014-9708 [MEDIUM] CWE-476 CVE-2014-9708: Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of serv
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
nvd