{"api_version":"1","generated_at":"2026-07-24T20:48:10+00:00","cve":"CVE-2019-7714","urls":{"html":"https://cve.report/CVE-2019-7714","api":"https://cve.report/api/cve/CVE-2019-7714.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-7714","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-7714"},"summary":{"title":"CVE-2019-7714","description":"An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Authentication header. However, when copying this header to parse, it does not check the size of the header, leading to a stack-based buffer overflow.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-03-26 01:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://github.com/bl4ckic3/GHS-Bugs","name":"https://github.com/bl4ckic3/GHS-Bugs","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"GitHub - bl4ckic3/GHS-Bugs: List of Vulnerabilities in Integrity RTOS","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.ghs.com/products/rtos/integrity.html","name":"https://www.ghs.com/products/rtos/integrity.html","refsource":"MISC","tags":["Vendor Advisory"],"title":"INTEGRITY Real-time Operating System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-7714","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-7714","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"7714","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ghs","cpe5":"integrity_rtos","cpe6":"5.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"7714","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ghs","cpe5":"integrity_rtos","cpe6":"5.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-7714","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Authentication header. However, when copying this header to parse, it does not check the size of the header, leading to a stack-based buffer overflow."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/bl4ckic3/GHS-Bugs","refsource":"MISC","name":"https://github.com/bl4ckic3/GHS-Bugs"},{"url":"https://www.ghs.com/products/rtos/integrity.html","refsource":"MISC","name":"https://www.ghs.com/products/rtos/integrity.html"}]}},"nvd":{"publishedDate":"2019-03-26 01:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:ghs:integrity_rtos:5.0.4:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"7714","Ordinal":"145537","Title":"CVE-2019-7714","CVE":"CVE-2019-7714","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"7714","Ordinal":"1","NoteData":"An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Authentication header. However, when copying this header to parse, it does not check the size of the header, leading to a stack-based buffer overflow.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"7714","Ordinal":"2","NoteData":"2019-03-25","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"7714","Ordinal":"3","NoteData":"2019-03-25","Type":"Other","Title":"Modified"}]}}}