Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 533

oracle-oval логотип

ELSA-2015-0983

больше 11 лет назад

ELSA-2015-0983: tomcat security update (MODERATE)

EPSS: Средний
debian логотип

CVE-2014-0227

больше 11 лет назад

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apach ...

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2014-0227

больше 11 лет назад

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2014-0227

больше 11 лет назад

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

CVSS2: 6.4
EPSS: Средний
redhat логотип

CVE-2014-0227

больше 11 лет назад

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2014-9635

почти 12 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-9634

почти 12 лет назад

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

CVSS2: 4.3
EPSS: Низкий
fstec логотип

BDU:2015-00410

около 12 лет назад

Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2013-4444

около 12 лет назад

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0 ...

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2013-4444

около 12 лет назад

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

CVSS2: 6.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
oracle-oval логотип
ELSA-2015-0983

ELSA-2015-0983: tomcat security update (MODERATE)

21%
Средний
больше 11 лет назад
debian логотип
CVE-2014-0227

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apach ...

CVSS2: 6.4
21%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-0227

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

CVSS2: 6.4
21%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-0227

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

CVSS2: 6.4
21%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-0227

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

CVSS2: 4.3
21%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-9635

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

CVSS2: 4.3
3%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-9634

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

CVSS2: 4.3
3%
Низкий
почти 12 лет назад
fstec логотип
BDU:2015-00410

Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 6.8
14%
Средний
около 12 лет назад
debian логотип
CVE-2013-4444

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0 ...

CVSS2: 6.8
14%
Средний
около 12 лет назад
nvd логотип
CVE-2013-4444

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

CVSS2: 6.8
14%
Средний
около 12 лет назад

Уязвимостей на страницу


Поделиться