Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 429

Количество 1 429

github логотип

GHSA-r84p-88g2-2vx2

около 4 лет назад

Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-qhqv-q4xg-f6g7

больше 4 лет назад

Apache Tomcat AJP Connector Information Leak

EPSS: Низкий
github логотип

GHSA-pxcx-cxq8-4mmw

около 4 лет назад

Uncontrolled Resource Consumption in Apache Tomcat

EPSS: Средний
github логотип

GHSA-pqr5-9v2j-44xg

больше 4 лет назад

Apache Tomcat DoS via Malicious Get Request

EPSS: Низкий
github логотип

GHSA-mgp5-rv84-w37q

5 месяцев назад

Apache Tomcat has an Improper Input Validation vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h3ch-5pp2-vh6w

около 4 лет назад

Improper socket reuse in Apache Tomcat

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-g7cf-wg27-qw87

около 4 лет назад

Jenkins secure flag not set on session cookies

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-cx6h-86xw-9x34

около 3 лет назад

Apache Tomcat - Fix for CVE-2023-24998 was incomplete

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-c7fc-mp9g-99j3

около 4 лет назад

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-95jq-rwvf-vjx4

4 месяца назад

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-7mg3-pr99-8rh7

около 4 лет назад

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

EPSS: Низкий
github логотип

GHSA-7jqf-v358-p8g7

больше 1 года назад

Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-7f6w-fhmr-j8hq

около 4 лет назад

Jenkins HttpOnly flag not Set for session cookies

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-59g9-7gfx-c72p

почти 5 лет назад

Infinite loop in Tomcat due to parsing error

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4prh-gqw8-rgh5

около 4 лет назад

Apache Tomcat Directory Traversal

EPSS: Критический
github логотип

GHSA-46j3-r4pj-4835

почти 8 лет назад

The host name verification missing in Apache Tomcat

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3v4j-mhgf-pf6w

около 4 лет назад

The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.

EPSS: Низкий
github логотип

GHSA-2rvv-w9r2-rg7m

около 5 лет назад

Information Disclosure in Apache Tomcat

CVSS3: 5.9
EPSS: Средний
ubuntu логотип

CVE-2026-29145

4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-29145

4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-r84p-88g2-2vx2

Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption

CVSS3: 7.5
73%
Высокий
около 4 лет назад
github логотип
GHSA-qhqv-q4xg-f6g7

Apache Tomcat AJP Connector Information Leak

7%
Низкий
больше 4 лет назад
github логотип
GHSA-pxcx-cxq8-4mmw

Uncontrolled Resource Consumption in Apache Tomcat

20%
Средний
около 4 лет назад
github логотип
GHSA-pqr5-9v2j-44xg

Apache Tomcat DoS via Malicious Get Request

10%
Низкий
больше 4 лет назад
github логотип
GHSA-mgp5-rv84-w37q

Apache Tomcat has an Improper Input Validation vulnerability

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-h3ch-5pp2-vh6w

Improper socket reuse in Apache Tomcat

CVSS3: 8.6
8%
Низкий
около 4 лет назад
github логотип
GHSA-g7cf-wg27-qw87

Jenkins secure flag not set on session cookies

CVSS3: 5.3
3%
Низкий
около 4 лет назад
github логотип
GHSA-cx6h-86xw-9x34

Apache Tomcat - Fix for CVE-2023-24998 was incomplete

CVSS3: 7.5
50%
Средний
около 3 лет назад
github логотип
GHSA-c7fc-mp9g-99j3

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

CVSS3: 7.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-95jq-rwvf-vjx4

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CVSS3: 9.1
1%
Низкий
4 месяца назад
github логотип
GHSA-7mg3-pr99-8rh7

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

7%
Низкий
около 4 лет назад
github логотип
GHSA-7jqf-v358-p8g7

Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability

CVSS3: 8.6
2%
Низкий
больше 1 года назад
github логотип
GHSA-7f6w-fhmr-j8hq

Jenkins HttpOnly flag not Set for session cookies

CVSS3: 5.3
3%
Низкий
около 4 лет назад
github логотип
GHSA-59g9-7gfx-c72p

Infinite loop in Tomcat due to parsing error

CVSS3: 7.5
7%
Низкий
почти 5 лет назад
github логотип
GHSA-4prh-gqw8-rgh5

Apache Tomcat Directory Traversal

91%
Критический
около 4 лет назад
github логотип
GHSA-46j3-r4pj-4835

The host name verification missing in Apache Tomcat

CVSS3: 7.5
21%
Средний
почти 8 лет назад
github логотип
GHSA-3v4j-mhgf-pf6w

The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.

7%
Низкий
около 4 лет назад
github логотип
GHSA-2rvv-w9r2-rg7m

Information Disclosure in Apache Tomcat

CVSS3: 5.9
23%
Средний
около 5 лет назад
ubuntu логотип
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

CVSS3: 9.1
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

CVSS3: 5.9
1%
Низкий
4 месяца назад

Уязвимостей на страницу