CVE-2014-9707: Embedthis GoAhead
High severity, CVSS 7.5. EPSS: 28.2% chance of exploitation in the next 30 days.
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.
Affected products
- Embedthis GoAhead: version 3.0.0 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; version 3.3.4 only; version 3.3.5 only; …
Published 2015-03-31. Last modified 2026-06-17.