Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.02014201520162017201820192020202120222023202420252026

Недавние уязвимости Tomcat

Количество 1 093

nvd логотип

CVE-2005-4836

больше 19 лет назад

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2005-4836

больше 19 лет назад

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not ...

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2005-4838

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the example web ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2005-4836

больше 19 лет назад

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2005-4838

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2005-3510

больше 19 лет назад

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2005-3510

больше 19 лет назад

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denia ...

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2005-3510

больше 19 лет назад

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

EPSS: Средний
nvd логотип

CVE-2005-3164

больше 19 лет назад

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-2090

почти 20 лет назад

Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

CVSS2: 4.3
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2005-4836

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

CVSS2: 7.8
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2005-4836

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not ...

CVSS2: 7.8
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2005-4838

Multiple cross-site scripting (XSS) vulnerabilities in the example web ...

CVSS2: 4.3
12%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2005-4836

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

CVSS2: 7.8
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2005-4838

Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries.

CVSS2: 4.3
12%
Средний
больше 19 лет назад
nvd логотип
CVE-2005-3510

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

CVSS2: 5
21%
Средний
больше 19 лет назад
debian логотип
CVE-2005-3510

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denia ...

CVSS2: 5
21%
Средний
больше 19 лет назад
redhat логотип
CVE-2005-3510

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

21%
Средний
больше 19 лет назад
nvd логотип
CVE-2005-3164

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

CVSS2: 2.6
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2005-2090

Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

CVSS2: 4.3
84%
Высокий
почти 20 лет назад

Уязвимостей на страницу


Поделиться