Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"

Количество 1 093

Количество 1 093

github логотип

GHSA-h6c8-x5r3-pm88

около 3 лет назад

Apache Tomcat Unrestricted file upload vulnerability

EPSS: Низкий
github логотип

GHSA-h6c8-rg87-f3pc

около 3 лет назад

Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users

EPSS: Средний
github логотип

GHSA-ggx9-4728-588r

около 3 лет назад

Apache Tomcat Directory Traversal vulnerability

EPSS: Средний
github логотип

GHSA-g8pj-r55q-5c2v

больше 1 года назад

Apache Tomcat Incomplete Cleanup vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g77g-vjjm-x83j

около 3 лет назад

Apache Tomcat Example Application CSRF and XSS Vulnerabilities

EPSS: Низкий
github логотип

GHSA-fjwp-r6fm-q6qw

около 3 лет назад

Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fj6c-prgj-gr3r

около 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-ff77-26x5-69cr

около 2 месяцев назад

Apache Tomcat Rewrite rule bypass

EPSS: Низкий
github логотип

GHSA-fccv-jmmp-qg76

больше 1 года назад

Apache Tomcat Improper Input Validation vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-f98p-9pp6-7q6c

около 3 лет назад

Apache Tomcat Cross-site scripting (XSS) vulnerability

EPSS: Средний
github логотип

GHSA-f632-9449-3j4w

7 месяцев назад

Apache Tomcat - XSS in generated JSPs

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-f4qf-m5gf-8jm8

больше 1 года назад

Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-f436-gr4m-qq5w

около 3 лет назад

The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.

EPSS: Средний
github логотип

GHSA-f2gq-p6qv-ccw4

около 3 лет назад

Tomcat Vulnerable to Web Cache Poisoning

EPSS: Высокий
github логотип

GHSA-cxg2-49rq-8gcr

около 3 лет назад

Apache Tomcat does not properly handle an invalid Transfer-Encoding header

EPSS: Высокий
github логотип

GHSA-cww4-vj5r-rx57

около 3 лет назад

Exposure of Sensitive Information in Apache Tomcat

EPSS: Высокий
github логотип

GHSA-cw29-r48c-h5f9

около 3 лет назад

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

EPSS: Низкий
github логотип

GHSA-cvx5-7vc7-rg77

около 3 лет назад

Tomcat uses trusted privileges when processing web.xml file

EPSS: Низкий
github логотип

GHSA-cpr9-82wf-f629

около 3 лет назад

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.

EPSS: Средний
github логотип

GHSA-cjg9-7x8h-6gw3

около 3 лет назад

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h6c8-x5r3-pm88

Apache Tomcat Unrestricted file upload vulnerability

6%
Низкий
около 3 лет назад
github логотип
GHSA-h6c8-rg87-f3pc

Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users

12%
Средний
около 3 лет назад
github логотип
GHSA-ggx9-4728-588r

Apache Tomcat Directory Traversal vulnerability

15%
Средний
около 3 лет назад
github логотип
GHSA-g8pj-r55q-5c2v

Apache Tomcat Incomplete Cleanup vulnerability

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-g77g-vjjm-x83j

Apache Tomcat Example Application CSRF and XSS Vulnerabilities

1%
Низкий
около 3 лет назад
github логотип
GHSA-fjwp-r6fm-q6qw

Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request

CVSS3: 7.5
3%
Низкий
около 3 лет назад
github логотип
GHSA-fj6c-prgj-gr3r

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

0%
Низкий
около 3 лет назад
github логотип
GHSA-ff77-26x5-69cr

Apache Tomcat Rewrite rule bypass

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-fccv-jmmp-qg76

Apache Tomcat Improper Input Validation vulnerability

CVSS3: 7.5
45%
Средний
больше 1 года назад
github логотип
GHSA-f98p-9pp6-7q6c

Apache Tomcat Cross-site scripting (XSS) vulnerability

49%
Средний
около 3 лет назад
github логотип
GHSA-f632-9449-3j4w

Apache Tomcat - XSS in generated JSPs

CVSS3: 6.1
2%
Низкий
7 месяцев назад
github логотип
GHSA-f4qf-m5gf-8jm8

Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information

CVSS3: 5.3
65%
Средний
больше 1 года назад
github логотип
GHSA-f436-gr4m-qq5w

The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.

23%
Средний
около 3 лет назад
github логотип
GHSA-f2gq-p6qv-ccw4

Tomcat Vulnerable to Web Cache Poisoning

84%
Высокий
около 3 лет назад
github логотип
GHSA-cxg2-49rq-8gcr

Apache Tomcat does not properly handle an invalid Transfer-Encoding header

81%
Высокий
около 3 лет назад
github логотип
GHSA-cww4-vj5r-rx57

Exposure of Sensitive Information in Apache Tomcat

80%
Высокий
около 3 лет назад
github логотип
GHSA-cw29-r48c-h5f9

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

0%
Низкий
около 3 лет назад
github логотип
GHSA-cvx5-7vc7-rg77

Tomcat uses trusted privileges when processing web.xml file

3%
Низкий
около 3 лет назад
github логотип
GHSA-cpr9-82wf-f629

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.

12%
Средний
около 3 лет назад
github логотип
GHSA-cjg9-7x8h-6gw3

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

6%
Низкий
около 3 лет назад

Уязвимостей на страницу