CVE Vulnerabilities

CVE-2014-9707

Published: Mar 31, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

Affected Software

NameVendorStart VersionEnd Version
GoaheadEmbedthis3.0.0 (including)3.0.0 (including)
GoaheadEmbedthis3.3.1 (including)3.3.1 (including)
GoaheadEmbedthis3.3.2 (including)3.3.2 (including)
GoaheadEmbedthis3.3.3 (including)3.3.3 (including)
GoaheadEmbedthis3.3.4 (including)3.3.4 (including)
GoaheadEmbedthis3.3.5 (including)3.3.5 (including)
GoaheadEmbedthis3.3.6 (including)3.3.6 (including)
GoaheadEmbedthis3.4.0 (including)3.4.0 (including)

References