← Vulnerability feed

Vulnerability record · CVE-2014-9708 · published 31 March 2015

CVE-2014-9708: Embedthis Appweb NULL pointer dereference via empty Range header

Oracle · Enterprise Communications Broker

Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 dereferences a NULL pointer when it receives a Range header with an empty value, such as "Range: x=,". A single malformed request can crash the web server process, so the flaw matters for availability of any service fronted by an affected Appweb build.

5.0 CVSS 2.0 Medium EPSS 56% · top 1.0% CWE-476 · NULL pointer dereference
5.0CVSS 2.0 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
28References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote crash with public exploit code and very high EPSS, though impact is limited to denial of service and the flaw is not in KEV.

What it is

Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 dereferences a NULL pointer when it receives a Range header with an empty value, such as "Range: x=,". A single malformed request can crash the web server process, so the flaw matters for availability of any service fronted by an affected Appweb build.

Impact

An unauthenticated remote attacker can crash the Appweb process, causing a denial of service. There is no evidence in the record of code execution, data disclosure, or data modification.

Attack surface

Reachable over the network via HTTP by sending a crafted Range header with an empty value; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Public exploit code and issue-tracking references are tagged Exploit, and EPSS is 0.56191 (99th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.

What to do

  • Upgrade Appweb to 4.6.6 or later, or 5.2.1 or later, which contain the fix.
  • Apply vendor patches for products that embed Appweb, including Oracle Enterprise Communications Broker and Juniper Junos J-Web, per their advisories.
  • If immediate patching is not possible, filter or reject HTTP requests containing empty or malformed Range header values at a reverse proxy or WAF.
  • Run Appweb under a supervisor that restarts the process automatically to limit outage duration from a crash.

Detection

  • Alert on Appweb process crashes or unexpected restarts correlated with inbound HTTP requests.
  • Inspect web server and proxy logs for Range headers with empty values, such as "Range: x=,".
  • Monitor for repeated malformed Range header requests from the same source IP.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Apr/19 Mailing ListThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Mar/158 ExploitMailing ListThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2015/03/28/2 Mailing ListPatch
http://www.openwall.com/lists/oss-security/2015/04/06/2 Mailing ListPatch
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html PatchThird Party Advisory
http://www.securityfocus.com/archive/1/535028/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/73407 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037007 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/embedthis/appweb/commit/7e6a925f5e86a19a7934a94bbd6959101d0b84eb#diff-7ca4d62c70220e0e226e7beac90c95d Broken LinkPatch
https://github.com/embedthis/appweb/issues/413 Broken LinkExploitIssue Tracking
https://security.paloaltonetworks.com/CVE-2014-9708 Third Party Advisory
https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved?l Third Party Advisory
http://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Apr/19 Mailing ListThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Mar/158 ExploitMailing ListThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2015/03/28/2 Mailing ListPatch
http://www.openwall.com/lists/oss-security/2015/04/06/2 Mailing ListPatch
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html PatchThird Party Advisory
http://www.securityfocus.com/archive/1/535028/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/73407 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037007 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/embedthis/appweb/commit/7e6a925f5e86a19a7934a94bbd6959101d0b84eb#diff-7ca4d62c70220e0e226e7beac90c95d Broken LinkPatch
https://github.com/embedthis/appweb/issues/413 Broken LinkExploitIssue Tracking
https://security.paloaltonetworks.com/CVE-2014-9708 Third Party Advisory
https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved?l Third Party Advisory

Track CVE-2014-9708 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-36845Juniper Junos OS J-Web PHP variable modification RCEJ-Web in Junos OS on EX Series and SRX Series mishandles the PHP PHPRC environment variable, letting a crafted request alter the PHP execution enviro…KEVEPSS 95%analysed9.8CVE-2020-1631Juniper Junos OS J-Web HTTP service path traversal and local file inclusionThe HTTP/HTTPS service behind J-Web, Web Authentication, Dynamic-VPN, Firewall Authentication Pass-Through with Web-Redirect, and ZTP in Junos OS doe…KEVEPSS 4.8%analysed6.7CVE-2025-21590Juniper Junos OS kernel improper isolation allows local code injectionJunos OS contains an improper isolation or compartmentalization flaw in the kernel that lets a local attacker with shell access inject arbitrary code…KEVEPSS 1.7%analysed5.3CVE-2023-36851Juniper Junos OS SRX J-Web missing authentication allows file upload/downloadJunos OS on SRX Series exposes webauth_operation.php without authentication, letting a network attacker upload and download arbitrary files through J…KEVEPSS 1.1%analysed5.3CVE-2023-36844Juniper Junos OS EX Series J-Web PHP Environment Variable ModificationJ-Web on Junos OS for EX Series fails to properly restrict external PHP variable modification, letting an unauthenticated network attacker alter impo…KEVEPSS 90%analysed5.3CVE-2023-36846Juniper Junos OS SRX J-Web Missing Authentication Allows File UploadJunos OS on SRX Series fails to require authentication for a critical function in user.php reachable through J-Web, letting an unauthenticated networ…KEVEPSS 93%analysed5.3CVE-2023-36847Juniper Junos OS EX Series J-Web installAppPackage.php missing authenticationJunos OS on EX Series exposes installAppPackage.php through J-Web without requiring authentication. An unauthenticated network attacker can upload ar…KEVEPSS 83%analysed10.0CVE-2021-31384Juniper junos improper authorization vulnerabilityDue to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2014-9708), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.