← back
CVE-2014-9708

CVE-2014-9708

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 56%
exploitation probability
56%top 1% of all CVEs
observed exploitation
nono source reports it
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Affected products
n/a · n/a