Cherokee

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 9
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2009-4587

    Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.

    Last Modified: Apr 23, 2026
    Published: Jan 07, 2010

    CVE-2009-3902

    Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL.

    Last Modified: Apr 23, 2026
    Published: Nov 06, 2009

    CVE-2006-1681

    Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.

    Last Modified: Apr 16, 2026
    Published: Apr 10, 2006

    CVE-2004-2171

    Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.

    Last Modified: Apr 16, 2026
    Published: Dec 31, 2004

    CVE-2004-1097

    Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.

    Last Modified: Apr 16, 2026
    Published: Dec 01, 2004
    Items Per Page
    Cherokee Vulnerabilities & Security CVEs | CVE-DB