CVE-2014-9708
UnknownEPSS 56.43%
Last modified
CVE-2014-9708 is a vulnerability of currently unknown severity. Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".. EPSS estimates a 56.43% chance of exploitation in the next 30 days.
Description
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Oracle | Enterprise Communications Broker | <= 2.0.0 | — |
| Embedthis | Appweb | < 4.6.6 | — |
| Embedthis | Appweb | >= 5.0.0, < 5.2.1 | — |
| Juniper | Junos | 12.1x46 | — |
| Juniper | Junos | 12.3x48 | — |
| Juniper | Junos | 15.1x49 | — |
| Juniper | Junos | 12.3 | — |
| Juniper | Junos | 15.1 | — |
| Juniper | Junos | 15.1x53 | — |
| Juniper | Junos | 16.1 | — |
| Juniper | Junos | 16.2 | — |
| Juniper | Junos | 17.1 | — |
| Juniper | Junos | 17.2 | R2 |
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
References
- http://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Apr/19Mailing List, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Mar/158Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2015/03/28/2Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2015/04/06/2Mailing List, Patch
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/archive/1/535028/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/73407Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037007Broken Link, Third Party Advisory, VDB Entry
- https://github.com/embedthis/appweb/issues/413Broken Link, Exploit, Issue Tracking
- https://security.paloaltonetworks.com/CVE-2014-9708Third Party Advisory
- http://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Apr/19Mailing List, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Mar/158Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2015/03/28/2Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2015/04/06/2Mailing List, Patch
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/archive/1/535028/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/73407Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037007Broken Link, Third Party Advisory, VDB Entry
- https://github.com/embedthis/appweb/issues/413Broken Link, Exploit, Issue Tracking
- https://security.paloaltonetworks.com/CVE-2014-9708Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-9708?
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
How severe is CVE-2014-9708?
Severity scoring for CVE-2014-9708 is pending analysis. The EPSS model estimates a 56.43% probability of exploitation in the next 30 days.
How do I fix CVE-2014-9708?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-9699The MakerBot Replicator 5G printer runs an Apache HTTP Serve…
- CVE-2014-9701Cross-site scripting (XSS) vulnerability in MantisBT before …
- CVE-2014-9702system/classes/DbPDO.php in Cmfive through 2015-03-15, when …7.5
- CVE-2014-9705Heap-based buffer overflow in the enchant_broker_request_dic…
- CVE-2014-9706The build_index_from_tree function in index.py in Dulwich be…
- CVE-2014-9707EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly hand…
- CVE-2014-9709The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier…
- CVE-2014-9710The Btrfs implementation in the Linux kernel before 3.19 doe…
- CVE-2014-9711Multiple cross-site scripting (XSS) vulnerabilities in the I…
- CVE-2014-9712Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 a…
- CVE-2014-9713The default slapd configuration in the Debian openldap packa…
- CVE-2014-9714Cross-site scripting (XSS) vulnerability in the WddxPacket::…
Are you affected by CVE-2014-9708?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
