Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.02014201520162017201820192020202120222023202420252026

Недавние уязвимости Tomcat

Количество 1 093

debian логотип

CVE-2002-0935

больше 22 лет назад

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, al ...

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2002-1148

больше 22 лет назад

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

EPSS: Средний
nvd логотип

CVE-2002-0493

почти 23 года назад

Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0682

почти 23 года назад

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2002-0682

почти 23 года назад

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remot ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2000-1210

около 23 лет назад

Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1563

больше 23 лет назад

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0829

больше 23 лет назад

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2001-0917

больше 23 лет назад

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0590

почти 24 года назад

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2002-0935

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, al ...

CVSS2: 5
2%
Низкий
больше 22 лет назад
redhat логотип
CVE-2002-1148

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

39%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-0493

Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.

CVSS2: 7.5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

CVSS2: 7.5
69%
Средний
почти 23 года назад
debian логотип
CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remot ...

CVSS2: 7.5
69%
Средний
почти 23 года назад
nvd логотип
CVE-2000-1210

Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.

CVSS2: 5
4%
Низкий
около 23 лет назад
nvd логотип
CVE-2001-1563

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-0829

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-0917

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

CVSS2: 5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-0590

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

CVSS2: 5
17%
Средний
почти 24 года назад

Уязвимостей на страницу


Поделиться