Skip to main content

Vendor archive

cherokee-project CVEs

Beta · best-effort

9 CVEs tagged to vendor cherokee-project1 Critical, 4 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2020-12845

Published Jul 27, 2020

Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20800

Published May 18, 2020

In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20799

Published May 18, 2020

In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20798

Published May 18, 2020

An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the w…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2191

Published Oct 7, 2011

Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests tha…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2190

Published Oct 7, 2011

The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determin…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4489

Published Jan 13, 2010

header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possib…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1