Total vulnerabilities in the database
Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.
Software | From | Fixed in |
---|---|---|
cherokee / cherokee_httpd | 0.4.6 | 0.4.6.x |
cherokee / cherokee_httpd | 0.2 | 0.2.x |
cherokee / cherokee_httpd | 0.1.6 | 0.1.6.x |
cherokee / cherokee_httpd | 0.2.6 | 0.2.6.x |
cherokee / cherokee_httpd | 0.2.5 | 0.2.5.x |
cherokee / cherokee_httpd | 0.4.17 | 0.4.17.x |
cherokee / cherokee_httpd | 0.1 | 0.1.x |
cherokee / cherokee_httpd | 0.4.8 | 0.4.8.x |
cherokee / cherokee_httpd | 0.2.7 | 0.2.7.x |
cherokee / cherokee_httpd | 0.4.7 | 0.4.7.x |
cherokee / cherokee_httpd | 0.1.5 | 0.1.5.x |