Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cherokee HIGH 7.5
CVE-2020-12845

Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the ser…

Fix: after 1.2.104
Fix from $1,950 2020-07-27
Cherokee CRITICAL 9.8
CVE-2019-20800

In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending man…

Fix: after 1.2.104
Fix from $2,300 2020-05-18
Cherokee HIGH 8.4
CVE-2019-20798

An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the …

Fix: after 1.2.104
Fix from $1,950 2020-05-18
Cherokee HIGH 7.5
CVE-2019-20799

In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.

Fix: after 1.2.104
Fix from $1,950 2020-05-18
Cherokee Web Server HIGH 7.5
CVE-2019-1010218

Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. …

Fix: after 1.2.103
Fix from $1,950 2019-07-22
Cherokee MEDIUM 6.8
CVE-2011-2191

Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of a…

Fix: after 1.2.98
Fix from $1,600 2011-10-07
Cherokee MEDIUM 5.0
CVE-2009-4489EPSS 10%

header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modi…

Fix: after 0.99.31
Fix from $1,600 2010-01-13