Логотип exploitDog
bind:CVE-2014-0119
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-0119

Количество 8

Количество 8

ubuntu логотип

CVE-2014-0119

около 11 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0119

около 11 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-0119

около 11 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-0119

около 11 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 d ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-prc3-7f44-w48j

около 3 лет назад

Missing XML Validation in Apache Tomcat

EPSS: Низкий
oracle-oval логотип

ELSA-2014-1034

почти 11 лет назад

ELSA-2014-1034: tomcat security update (LOW)

EPSS: Низкий
fstec логотип

BDU:2015-00409

около 11 лет назад

Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

CVSS2: 4.3
EPSS: Низкий
oracle-oval логотип

ELSA-2014-1038

почти 11 лет назад

ELSA-2014-1038: tomcat6 security update (LOW)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-0119

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 4.3
5%
Низкий
около 11 лет назад
redhat логотип
CVE-2014-0119

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 2.1
5%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-0119

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 4.3
5%
Низкий
около 11 лет назад
debian логотип
CVE-2014-0119

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 d ...

CVSS2: 4.3
5%
Низкий
около 11 лет назад
github логотип
GHSA-prc3-7f44-w48j

Missing XML Validation in Apache Tomcat

5%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2014-1034

ELSA-2014-1034: tomcat security update (LOW)

почти 11 лет назад
fstec логотип
BDU:2015-00409

Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

CVSS2: 4.3
5%
Низкий
около 11 лет назад
oracle-oval логотип
ELSA-2014-1038

ELSA-2014-1038: tomcat6 security update (LOW)

почти 11 лет назад

Уязвимостей на страницу