Vulnerability record · CVE-2014-9708 · published 31 March 2015
CVE-2014-9708: Embedthis Appweb NULL pointer dereference via empty Range header
Oracle · Enterprise Communications Broker
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 dereferences a NULL pointer when it receives a Range header with an empty value, such as "Range: x=,". A single malformed request can crash the web server process, so the flaw matters for availability of any service fronted by an affected Appweb build.
Description
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityUnauthenticated remote crash with public exploit code and very high EPSS, though impact is limited to denial of service and the flaw is not in KEV.
What it is
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 dereferences a NULL pointer when it receives a Range header with an empty value, such as "Range: x=,". A single malformed request can crash the web server process, so the flaw matters for availability of any service fronted by an affected Appweb build.
Impact
An unauthenticated remote attacker can crash the Appweb process, causing a denial of service. There is no evidence in the record of code execution, data disclosure, or data modification.
Attack surface
Reachable over the network via HTTP by sending a crafted Range header with an empty value; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Public exploit code and issue-tracking references are tagged Exploit, and EPSS is 0.56191 (99th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Upgrade Appweb to 4.6.6 or later, or 5.2.1 or later, which contain the fix.
- Apply vendor patches for products that embed Appweb, including Oracle Enterprise Communications Broker and Juniper Junos J-Web, per their advisories.
- If immediate patching is not possible, filter or reject HTTP requests containing empty or malformed Range header values at a reverse proxy or WAF.
- Run Appweb under a supervisor that restarts the process automatically to limit outage duration from a crash.
Detection
- Alert on Appweb process crashes or unexpected restarts correlated with inbound HTTP requests.
- Inspect web server and proxy logs for Range headers with empty values, such as "Range: x=,".
- Monitor for repeated malformed Range header requests from the same source IP.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-9708 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9708), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.