Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 533

Количество 1 533

debian логотип

CVE-2002-1895

больше 23 лет назад

The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1567

почти 23 года назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2002-1567

почти 23 года назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows r ...

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2002-1394

почти 24 года назад

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

EPSS: Низкий
nvd логотип

CVE-2002-1394

больше 23 лет назад

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2002-1394

больше 23 лет назад

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet a ...

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2002-1148

почти 24 года назад

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

EPSS: Средний
nvd логотип

CVE-2002-1148

почти 24 года назад

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2002-1148

почти 24 года назад

The default servlet (org.apache.catalina.servlets.DefaultServlet) in T ...

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0936

почти 24 года назад

The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2002-0936

почти 24 года назад

The Java Server Pages (JSP) engine in Tomcat allows web page owners to ...

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0935

почти 24 года назад

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2002-0935

почти 24 года назад

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, al ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0682

около 24 лет назад

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2002-0682

около 24 лет назад

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remot ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0493

около 24 лет назад

Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1563

больше 24 лет назад

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0917

почти 25 лет назад

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0829

почти 25 лет назад

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2001-0590

около 25 лет назад

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2002-1895

The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using ...

CVSS2: 5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1567

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

CVSS2: 6.8
27%
Средний
почти 23 года назад
debian логотип
CVE-2002-1567

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows r ...

CVSS2: 6.8
27%
Средний
почти 23 года назад
redhat логотип
CVE-2002-1394

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

6%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1394

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

CVSS2: 7.5
6%
Низкий
больше 23 лет назад
debian логотип
CVE-2002-1394

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet a ...

CVSS2: 7.5
6%
Низкий
больше 23 лет назад
redhat логотип
CVE-2002-1148

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

19%
Средний
почти 24 года назад
nvd логотип
CVE-2002-1148

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

CVSS2: 5
19%
Средний
почти 24 года назад
debian логотип
CVE-2002-1148

The default servlet (org.apache.catalina.servlets.DefaultServlet) in T ...

CVSS2: 5
19%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0936

The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).

CVSS2: 5
27%
Средний
почти 24 года назад
debian логотип
CVE-2002-0936

The Java Server Pages (JSP) engine in Tomcat allows web page owners to ...

CVSS2: 5
27%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0935

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.

CVSS2: 5
8%
Низкий
почти 24 года назад
debian логотип
CVE-2002-0935

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, al ...

CVSS2: 5
8%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

CVSS2: 7.5
14%
Средний
около 24 лет назад
debian логотип
CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remot ...

CVSS2: 7.5
14%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0493

Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.

CVSS2: 7.5
4%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1563

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

CVSS2: 7.5
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0917

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

CVSS2: 5
8%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0829

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
12%
Средний
почти 25 лет назад
nvd логотип
CVE-2001-0590

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

CVSS2: 5
11%
Средний
около 25 лет назад

Уязвимостей на страницу