Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.02014201520162017201820192020202120222023202420252026

Недавние уязвимости Tomcat

Количество 1 156

debian логотип

CVE-2006-7195

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Ap ...

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2007-1858

больше 18 лет назад

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4 ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2007-1358

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".

CVSS2: 2.6
EPSS: Средний
ubuntu логотип

CVE-2006-7196

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

CVSS2: 4.3
EPSS: Высокий
ubuntu логотип

CVE-2007-1858

больше 18 лет назад

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-7195

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2006-7196

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

EPSS: Высокий
nvd логотип

CVE-2006-7197

больше 18 лет назад

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2006-7197

больше 18 лет назад

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for ...

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2006-7197

больше 18 лет назад

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

CVSS2: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2006-7195

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Ap ...

CVSS2: 4.3
11%
Средний
больше 18 лет назад
debian логотип
CVE-2007-1858

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4 ...

CVSS2: 2.6
7%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1358

Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".

CVSS2: 2.6
45%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2006-7196

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

CVSS2: 4.3
78%
Высокий
больше 18 лет назад
ubuntu логотип
CVE-2007-1858

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

CVSS2: 2.6
7%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-7195

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.

CVSS2: 4.3
11%
Средний
больше 18 лет назад
redhat логотип
CVE-2006-7196

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

78%
Высокий
больше 18 лет назад
nvd логотип
CVE-2006-7197

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

CVSS2: 7.8
2%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-7197

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for ...

CVSS2: 7.8
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-7197

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

CVSS2: 7.8
2%
Низкий
больше 18 лет назад

Уязвимостей на страницу


Поделиться