Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Goahead CRITICAL 9.8
CVE-2021-41615

websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise valu…

Mitigation only
Fix from $2,300 2022-08-08
Appweb HIGH 7.5
CVE-2021-33254

An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stre…

Patch available
Fix from $1,950 2022-06-02
Goahead CRITICAL 9.8
CVE-2021-43298

The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This me…

Fix: 5.1.4+
Fix from $2,300 2022-01-25
Goahead CRITICAL 9.8
CVE-2021-42342EPSS 59%

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without bein…

Fix: 5.1.5+
Fix from $2,300 2021-10-14
Goahead HIGH 8.8
CVE-2020-15688

The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthentica…

Fix: 5.1.2+
Fix from $1,950 2020-07-23
Appweb HIGH 7.5
CVE-2020-15689

Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This…

Fix: 7.2.2 / 8.1.0+
Fix from $1,950 2020-07-13
Goahead CRITICAL 9.8
CVE-2019-5096EPSS 67%

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application …

No fix yet
Fix from $2,300 2019-12-03
Goahead HIGH 7.5
CVE-2019-5097EPSS 45%

A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5…

No fix yet
Fix from $1,950 2019-12-03
Goahead MEDIUM 5.3
CVE-2019-19240

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that …

Fix: 5.0.1+
Fix from $1,600 2019-11-22
Goahead HIGH 8.6
CVE-2019-16645EPSS 8%

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostna…

No fix yet
Fix from $1,950 2019-09-20
Goahead HIGH 7.5
CVE-2019-12822EPSS 9%

In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory refe…

Fix: 4.1.1 / 5.0.1+
Fix from $1,950 2019-06-14
Appweb HIGH 7.5
CVE-2018-15504

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with tim…

Fix: 4.0.1 / 7.0.2+
Fix from $1,950 2018-08-18
Appweb HIGH 7.5
CVE-2018-15505

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field …

Fix: 4.0.1 / 7.0.2+
Fix from $1,950 2018-08-18
Appweb HIGH 8.1
CVE-2018-8715EPSS 23%

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forge…

Fix: after 7.0.2
Fix from $1,950 2018-03-15
Goahead CRITICAL 9.8
CVE-2017-1000471EPSS 9%

EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of …

Patch available
Fix from $2,300 2018-01-03
Goahead Web Server HIGH 7.5
CVE-2017-1000470EPSS 8%

EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.

Patch available
Fix from $1,950 2018-01-03
Goahead HIGH 8.1
CVE-2017-17562 KEVEPSS 96%

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializi…

Fix: 3.6.5+
Fix from $1,950 2017-12-12
Goahead HIGH 7.5
CVE-2017-14149EPSS 6%

GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" reques…

No fix yet
Fix from $1,950 2017-09-05
Goahead CRITICAL 9.8
CVE-2017-5674EPSS 22%

A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft …

No fix yet
Fix from $2,300 2017-03-13
Goahead HIGH 8.8
CVE-2017-5675

A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label…

No fix yet
Fix from $1,950 2017-03-13
Goahead HIGH 7.5
CVE-2014-9707EPSS 28%

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct direct…

Patch available
Fix from $1,950 2015-03-31