Show filters
203 Total Results
Displaying 191-200 of 203
Sort by:
Attacker Value
Unknown
CVE-2011-2190
Disclosure Date: October 07, 2011 (last updated October 04, 2023)
The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.
0
Attacker Value
Unknown
CVE-2009-4489
Disclosure Date: January 13, 2010 (last updated October 04, 2023)
header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown
CVE-2009-4587
Disclosure Date: January 07, 2010 (last updated October 04, 2023)
Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.
0
Attacker Value
Unknown
CVE-2009-3902
Disclosure Date: November 06, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL.
0
Attacker Value
Unknown
CVE-2008-7162
Disclosure Date: September 04, 2009 (last updated October 04, 2023)
Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504.
0
Attacker Value
Unknown
CVE-2008-4504
Disclosure Date: October 09, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in Mplayer.exe in Herosoft Inc. Hero DVD Player 3.0.8 allows user-assisted remote attackers to execute arbitrary code via an M3u file with a "long entry." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-1681
Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.
0
Attacker Value
Unknown
CVE-2004-1097
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.
0
Attacker Value
Unknown
CVE-2004-2171
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.
0
Attacker Value
Unknown
CVE-2004-1946
Disclosure Date: April 19, 2004 (last updated February 22, 2025)
Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.
0