Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.02014201520162017201820192020202120222023202420252026

Недавние уязвимости Tomcat

Количество 1 245

github логотип

GHSA-w3j5-q8f2-3cqq

больше 3 лет назад

Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-698c-2x4j-g9gq

больше 3 лет назад

Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-73rx-3f9r-x949

больше 3 лет назад

Insufficient Verification of Data Authenticity in Apache Tomcat

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-372q-33vh-8mpc

больше 3 лет назад

Inconsistent documentation in Apache Tomcat

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fjwp-r6fm-q6qw

больше 3 лет назад

Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjgh-84hx-56c5

больше 3 лет назад

Unrestricted Upload of File with Dangerous Type Apache Tomcat

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-68g5-8q7f-m384

больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h3ch-5pp2-vh6w

больше 3 лет назад

Improper socket reuse in Apache Tomcat

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2022-25762

больше 3 лет назад

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-25762

больше 3 лет назад

If a web application sends a WebSocket message concurrently with the W ...

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-w3j5-q8f2-3cqq

Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat

CVSS3: 7.5
11%
Средний
больше 3 лет назад
github логотип
GHSA-698c-2x4j-g9gq

Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-73rx-3f9r-x949

Insufficient Verification of Data Authenticity in Apache Tomcat

CVSS3: 4.3
5%
Низкий
больше 3 лет назад
github логотип
GHSA-372q-33vh-8mpc

Inconsistent documentation in Apache Tomcat

CVSS3: 5.3
4%
Низкий
больше 3 лет назад
github логотип
GHSA-fjwp-r6fm-q6qw

Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xjgh-84hx-56c5

Unrestricted Upload of File with Dangerous Type Apache Tomcat

CVSS3: 8.1
94%
Критический
больше 3 лет назад
github логотип
GHSA-68g5-8q7f-m384

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-h3ch-5pp2-vh6w

Improper socket reuse in Apache Tomcat

CVSS3: 8.6
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the W ...

CVSS3: 8.6
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться