7.5

CVE-2017-14149

Exploit

GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.

Data is provided by the National Vulnerability Database (NVD)
EmbedthisGoahead Version3.4.0
EmbedthisGoahead Version3.4.1
EmbedthisGoahead Version3.4.2
EmbedthisGoahead Version3.4.3
EmbedthisGoahead Version3.4.4
EmbedthisGoahead Version3.4.5
EmbedthisGoahead Version3.4.6
EmbedthisGoahead Version3.4.7
EmbedthisGoahead Version3.4.8
EmbedthisGoahead Version3.4.9
EmbedthisGoahead Version3.4.10
EmbedthisGoahead Version3.4.11
EmbedthisGoahead Version3.4.12
EmbedthisGoahead Version3.5.0
EmbedthisGoahead Version3.6.0
EmbedthisGoahead Version3.6.1
EmbedthisGoahead Version3.6.2
EmbedthisGoahead Version3.6.3
EmbedthisGoahead Version3.6.4
EmbedthisGoahead Version3.6.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.534
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.