VYPR

GoAhead

by Goahead

CVEs (6)

  • CVE-2019-5096CriDec 3, 2019
    risk 0.69cvss 9.8epss 0.67

    An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the…

  • CVE-2021-42342CriOct 14, 2021
    risk 0.68cvss 9.8epss 0.59

    An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

  • CVE-2019-5097HigDec 3, 2019
    risk 0.52cvss 7.5epss 0.45

    A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to an infinite loop in the process. The request can be…

  • CVE-2017-14149HigSep 5, 2017
    risk 0.49cvss 7.5epss 0.06

    GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.

  • CVE-2024-3187MedOct 17, 2024
    risk 0.38cvss 5.9epss 0.01

    This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.0.0. These are caused by JST values not being nulled when freed during parsing of JST templates. If the ME_GOAHEAD_JAVASCRIPT flag is enabled, a remote…

  • CVE-2024-3186MedOct 17, 2024
    risk 0.34cvss 5.3epss 0.00

    CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when compiled with the ME_GOAHEAD_JAVASCRIPT flag. This vulnerability allows a remote attacker with the privileges to modify JavaScript template (JST) files to…

VYPR — Vulnerability Intelligence