An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
|
History
21 Nov 2024, 03:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/embedthis/appweb/commit/66067ae6d1fa08b37a270e7dc1821df52ed2daef - Patch, Third Party Advisory | |
References | () https://github.com/embedthis/appweb/issues/605Â - Exploit, Patch, Third Party Advisory | |
References | () https://github.com/embedthis/goahead/issues/264Â - Exploit, Patch, Third Party Advisory | |
References | () https://supportportal.juniper.net/s/article/2019-07-Security-Bulletin-Junos-OS-J-Web-Denial-of-Service-due-to-multiple-vulnerabilities-in-Embedthis-Appweb-Server - Third Party Advisory | |
References | () https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved - Third Party Advisory |
13 Jun 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2018-08-18 03:29
Updated : 2024-11-21 03:50
NVD link : CVE-2018-15504
Mitre link : CVE-2018-15504
CVE.ORG link : CVE-2018-15504
JSON object : View
Products Affected
juniper
- ex2300-24p
- ex2300-24mp
- ex4550-vc
- ex4300
- ex8200
- ex9251
- ex4550\/vc
- srx550m
- ex4650
- ex4300-48p-s
- ex4300-24p-s
- ex2300-48mp
- mx240
- mx
- srx300
- ex4300-48tdc
- ptx3000
- srx4100
- ptx5000
- ex4300-mp
- ex8216
- srx345
- mx10016
- mx40
- mx5
- ex4300-48mp-s
- mx2020
- mx150
- srx3400
- ex4300-32f
- ptx10004
- ex4300-48t-s
- ex4300-24t
- srx240
- ptx10003
- srx100
- t640
- ptx10016
- srx320
- mx10003
- ex3200
- mx204
- ptx10002
- ex4300-48tafi
- srx550
- srx340
- mx10
- mx80
- ex4600
- mx2010
- ptx10003_81cd
- ex4300-48p
- ptx10001
- ex2300
- ex4200
- ex2300-48p
- ex2200-vc
- ex9214
- ex4300-48mp
- mx10008
- ex9200
- ex9208
- srx210
- srx5000
- ex3400
- ptx10008
- ex2200-c
- ptx10002-60c
- t320
- ptx10001-36mr
- mx10000
- ex4300-24t-s
- srx1500
- ex2300-24t
- ptx1000
- ex2300-c
- srx110
- ex9250
- ex8208
- ex3300-vc
- t1600
- srx5800
- t4000
- srx1400
- ex6210
- ex4300-24p
- ptx1000-72q
- srx4200
- ptx10003_160c
- ex4300-32f-s
- srx240m
- ex4500-vc
- ex9204
- srx220
- ex4300-48t-dc-afi
- srx5600
- ex9253
- ex4500
- srx4600
- ex6200
- ptx10003_80c
- ex4300-32f-dc
- mx104
- srx550_hm
- ex2300m
- mx2008
- ex2200
- ex4300-48t-afi
- ptx100016
- srx380
- ptx10000
- ex2300-48t
- ex3300
- ex4300-48t
- mx960
- srx4000
- ex4300m
- ex4300-vc
- ex4400
- srx650
- ex4200-vc
- junos
- mx480
- ex8200-vc
- srx3600
- ex4550
- ex4300-48t-dc
- ex4600-vc
- ex4300-48tdc-afi
- srx5400
- qfx10000
- srx240h2
embedthis
- appweb
- goahead
CWE
CWE-476
NULL Pointer Dereference