CVE-2014-9708
UnknownEPSS 56.43%
Last modified
CVE-2014-9708 is a vulnerability of currently unknown severity. Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".. EPSS estimates a 56.43% chance of exploitation in the next 30 days.
Description
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Oracle | Enterprise Communications Broker | <= 2.0.0 | — |
| Embedthis | Appweb | < 4.6.6 | — |
| Embedthis | Appweb | >= 5.0.0, < 5.2.1 | — |
| Juniper | Junos | 12.1x46 | — |
| Juniper | Junos | 12.3x48 | — |
| Juniper | Junos | 15.1x49 | — |
| Juniper | Junos | 12.3 | — |
| Juniper | Junos | 15.1 | — |
| Juniper | Junos | 15.1x53 | — |
| Juniper | Junos | 16.1 | — |
| Juniper | Junos | 16.2 | — |
| Juniper | Junos | 17.1 | — |
| Juniper | Junos | 17.2 | R2 |
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
References
- http://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Apr/19Mailing List, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Mar/158Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2015/03/28/2Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2015/04/06/2Mailing List, Patch
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/archive/1/535028/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/73407Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037007Broken Link, Third Party Advisory, VDB Entry
- https://github.com/embedthis/appweb/issues/413Broken Link, Exploit, Issue Tracking
- https://security.paloaltonetworks.com/CVE-2014-9708Third Party Advisory
- http://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Apr/19Mailing List, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Mar/158Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2015/03/28/2Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2015/04/06/2Mailing List, Patch
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/archive/1/535028/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/73407Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037007Broken Link, Third Party Advisory, VDB Entry
- https://github.com/embedthis/appweb/issues/413Broken Link, Exploit, Issue Tracking
- https://security.paloaltonetworks.com/CVE-2014-9708Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-9708?
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
How severe is CVE-2014-9708?
Severity scoring for CVE-2014-9708 is pending analysis. The EPSS model estimates a 56.43% probability of exploitation in the next 30 days.
How do I fix CVE-2014-9708?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2014-9708?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
