CRITICAL🇵🇱 Wersja polska

CVE-2017-1000471

CVSS 9.8v3.0pub. 2018-01-03upd. 2024-11-21

EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Embedthis Goahead

    APP
    Embedthis
    4.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2021-41615CRITICAL9.8PL ✓same product

GoAhead WebServer: niewystarczająca entropia nonce w uwierzytelnianiu HTTP Digest

CVE-2021-43298CRITICAL9.8PL ✓same product

Embedthis GoAhead: brute-force hasła HTTP Basic Auth przez timing attack

CVE-2021-42342CRITICAL9.8PL ✓same product

GoAhead: tunelowanie zmiennych środowiskowych do skryptów CGI przez upload pliku

CVE-2019-5096CRITICAL9.8PL ✓same product

GoAhead Web Server: RCE przez use-after-free w obsłudze multipart/form-data

CVE-2017-5674CRITICAL9.8PL ✓same product

Ujawnienie hasła konfiguracyjnego w kamerach IP przez GoAhead