VYPR
High severity7.5NVD Advisory· Published Jul 13, 2020· Updated Jun 17, 2026

CVE-2020-15689

CVE-2020-15689

Description

Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.

Affected products

3
  • Embedthis/Appweb2 versions
    cpe:2.3:a:embedthis:appweb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:embedthis:appweb:*:*:*:*:*:*:*:*range: <7.2.2
    • (no CPE)range: <7.2.2, <8.1.0
  • Appweb/Appwebdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.