Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 429

nvd логотип

CVE-2006-7195

около 19 лет назад

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-1858

около 19 лет назад

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4 ...

CVSS2: 2.6
EPSS: Средний
debian логотип

CVE-2006-7195

около 19 лет назад

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Ap ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-1358

около 19 лет назад

Cross-site scripting (XSS) vulnerability in certain applications using ...

CVSS2: 2.6
EPSS: Средний
debian логотип

CVE-2006-7196

около 19 лет назад

Cross-site scripting (XSS) vulnerability in the calendar application e ...

CVSS2: 4.3
EPSS: Высокий
ubuntu логотип

CVE-2006-7196

около 19 лет назад

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

CVSS2: 4.3
EPSS: Высокий
ubuntu логотип

CVE-2007-1358

около 19 лет назад

Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".

CVSS2: 2.6
EPSS: Средний
ubuntu логотип

CVE-2007-1858

около 19 лет назад

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

CVSS2: 2.6
EPSS: Средний
ubuntu логотип

CVE-2006-7195

около 19 лет назад

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2006-7196

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2006-7195

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.

CVSS2: 4.3
5%
Низкий
около 19 лет назад
debian логотип
CVE-2007-1858

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4 ...

CVSS2: 2.6
18%
Средний
около 19 лет назад
debian логотип
CVE-2006-7195

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Ap ...

CVSS2: 4.3
5%
Низкий
около 19 лет назад
debian логотип
CVE-2007-1358

Cross-site scripting (XSS) vulnerability in certain applications using ...

CVSS2: 2.6
20%
Средний
около 19 лет назад
debian логотип
CVE-2006-7196

Cross-site scripting (XSS) vulnerability in the calendar application e ...

CVSS2: 4.3
72%
Высокий
около 19 лет назад
ubuntu логотип
CVE-2006-7196

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

CVSS2: 4.3
72%
Высокий
около 19 лет назад
ubuntu логотип
CVE-2007-1358

Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".

CVSS2: 2.6
20%
Средний
около 19 лет назад
ubuntu логотип
CVE-2007-1858

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

CVSS2: 2.6
18%
Средний
около 19 лет назад
ubuntu логотип
CVE-2006-7195

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.

CVSS2: 4.3
5%
Низкий
около 19 лет назад
redhat логотип
CVE-2006-7196

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

72%
Высокий
больше 19 лет назад

Уязвимостей на страницу


Поделиться