Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 423

debian логотип

CVE-2002-0935

почти 24 года назад

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, al ...

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2002-1148

почти 24 года назад

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

EPSS: Средний
nvd логотип

CVE-2002-0493

почти 24 года назад

Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0682

около 24 лет назад

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2002-0682

около 24 лет назад

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remot ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2000-1210

больше 24 лет назад

Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1563

больше 24 лет назад

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0829

больше 24 лет назад

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2001-0917

больше 24 лет назад

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0590

почти 25 лет назад

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2002-0935

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, al ...

CVSS2: 5
8%
Низкий
почти 24 года назад
redhat логотип
CVE-2002-1148

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

17%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0493

Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.

CVSS2: 7.5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

CVSS2: 7.5
12%
Средний
около 24 лет назад
debian логотип
CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remot ...

CVSS2: 7.5
12%
Средний
около 24 лет назад
nvd логотип
CVE-2000-1210

Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.

CVSS2: 5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1563

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

CVSS2: 7.5
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0829

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
14%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-0917

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

CVSS2: 5
8%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0590

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

CVSS2: 5
11%
Средний
почти 25 лет назад

Уязвимостей на страницу


Поделиться