Cherokee

Vendor:

First CVE: Jan 7, 2010 · Active for 16 years

9
Total CVEs
More Total CVEs than 87% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cherokee over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 7, 2010
16 years ago
Most Recent CVE
Jul 27, 2020
2,192 days ago

CVE Severity & Scoring

Cherokee9 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (44.4%)
Unknown5 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (44.4%)
High0 (0.0%)
Unknown5 (55.6%)
User Interaction
None3 (33.3%)
Unknown5 (55.6%)
Required1 (11.1%)
Privileges Required
Low0 (0.0%)
High1 (11.1%)
None3 (33.3%)
Unknown5 (55.6%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstra
May 18, 20209.831NONO
header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibl
Jan 13, 20105.028NOYES
An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the we
May 18, 20208.427NONO
In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.
May 18, 20207.526NONO
Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.
Jan 7, 20105.026NOYES
Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that
Oct 7, 20116.823NONO
Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request
Jul 27, 20207.520NONO
The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which
Jul 2, 20146.819NONO
The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine
Oct 7, 20112.114NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Cherokee

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.2.9916.82.8%00
1.2.9816.82.8%00
1.2.235.21.5%00
1.2.10216.82.8%00
1.2.10116.82.8%00
1.2.124.50.9%00
1.2.024.50.9%00
1.0.924.50.9%00
1.0.824.50.9%00
1.0.724.50.9%00
1.0.624.50.9%00
1.0.524.50.9%00
1.0.424.50.9%00
1.0.324.50.9%00
1.0.2024.50.9%00
1.0.224.50.9%00
1.0.1924.50.9%00
1.0.1824.50.9%00
1.0.1724.50.9%00
1.0.1624.50.9%00