Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
|
History
21 Nov 2024, 02:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.html - Exploit, Third Party Advisory, VDB Entry | |
References | () http://seclists.org/fulldisclosure/2015/Apr/19Â - Mailing List, Third Party Advisory, VDB Entry | |
References | () http://seclists.org/fulldisclosure/2015/Mar/158Â - Exploit, Mailing List, Third Party Advisory, VDB Entry | |
References | () http://www.openwall.com/lists/oss-security/2015/03/28/2Â - Mailing List, Patch | |
References | () http://www.openwall.com/lists/oss-security/2015/04/06/2Â - Mailing List, Patch | |
References | () http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html - Patch, Third Party Advisory | |
References | () http://www.securityfocus.com/archive/1/535028/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threaded - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/73407Â - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1037007Â - Broken Link, Third Party Advisory, VDB Entry | |
References | () https://github.com/embedthis/appweb/commit/7e6a925f5e86a19a7934a94bbd6959101d0b84eb#diff-7ca4d62c70220e0e226e7beac90c95d9L17348Â - Broken Link, Patch | |
References | () https://github.com/embedthis/appweb/issues/413Â - Broken Link, Exploit, Issue Tracking | |
References | () https://security.paloaltonetworks.com/CVE-2014-9708Â - Third Party Advisory | |
References | () https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved?language=en_USÂ - Third Party Advisory |
13 Jun 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2015-03-31 14:59
Updated : 2025-04-12 10:46
NVD link : CVE-2014-9708
Mitre link : CVE-2014-9708
CVE.ORG link : CVE-2014-9708
JSON object : View
Products Affected
juniper
- ex8208
- ex8200-vc
- ex2300-24p
- ex6210
- mx10003
- ex4300-48t-dc
- srx5600
- ex4300-48t
- ex4300-48t-afi
- ex9253
- srx320
- ex4300-24p
- ex4300-24t-s
- srx1500
- ex4300-48mp-s
- srx4600
- mx10
- ptx1000-72q
- t320
- ex4200-vc
- srx650
- ptx10008
- srx110
- ex4650
- ex2200-vc
- ex2300-c
- srx240h2
- srx210
- ex9214
- mx104
- ex4550\/vc
- mx150
- ex2200
- ex4550
- ex4300-24p-s
- ex4300-vc
- ex3200
- srx345
- ex3400
- ex2300-24mp
- srx550_hm
- mx5
- srx3400
- ptx10016
- srx4000
- mx10000
- srx4100
- ex4300-48t-s
- ex4550-vc
- ex4300-32f-dc
- mx960
- srx1400
- ex2300-24t
- ptx10003_160c
- srx300
- ex4300-mp
- srx4200
- ex4300-48p
- ex2300-48p
- ex4300-32f
- srx5400
- ex9208
- ex4300-48p-s
- ptx10003_80c
- mx240
- srx380
- ptx5000
- srx550m
- ex8216
- ex2300-48mp
- ptx10001
- ptx3000
- ptx10003
- ex2200-c
- mx2020
- ex4300-48tdc-afi
- t1600
- mx10008
- ex4600
- srx5000
- ex4300-32f-s
- ex4300-48mp
- ptx100016
- ex4300-48tafi
- ex4400
- ptx1000
- ex9250
- ptx10001-36mr
- ex4600-vc
- srx340
- ex4300-48t-dc-afi
- srx100
- ex9200
- t4000
- ex4500
- ptx10003_81cd
- qfx10000
- mx10016
- ex3300
- mx2010
- srx5800
- mx204
- srx550
- ex2300
- mx40
- ex3300-vc
- ex8200
- ptx10000
- ex9204
- mx
- ptx10002-60c
- ex4300
- ex9251
- ex6200
- mx80
- ex4300m
- ex4300-24t
- t640
- mx2008
- ex4500-vc
- ex2300-48t
- ex2300m
- ex4300-48tdc
- junos
- srx240
- srx220
- srx240m
- srx3600
- ptx10002
- mx480
- ptx10004
- ex4200
oracle
- enterprise_communications_broker
embedthis
- appweb
CWE
CWE-476
NULL Pointer Dereference