Количество 1 427
Количество 1 427
BDU:2021-06115
Уязвимость сервера приложений Apache Tomcat, связанная с утечкой памяти, позволяющая нарушителю вызвать отказ в обслуживании
GHSA-xjgh-84hx-56c5
Unrestricted Upload of File with Dangerous Type Apache Tomcat
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22 ...
BDU:2023-06559
Уязвимость реализации протокола HTTP/2, связанная с возможностью формирования потока запросов в рамках уже установленного сетевого соединения, без открытия новых сетевых соединений и без подтверждения получения пакетов, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2023:4624-1
Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container
SUSE-SU-2023:4492-1
Security update for nghttp2
SUSE-SU-2023:4295-1
Security update for nodejs10
SUSE-SU-2023:4200-1
Security update for nghttp2
SUSE-SU-2023:4199-1
Security update for nghttp2
SUSE-SU-2023:4163-1
Security update for netty, netty-tcnative
RLSA-2023:6120
Moderate: nginx:1.22 security update
RLSA-2023:5989
Important: varnish security update
RLSA-2023:5928
Important: tomcat security update
RLSA-2023:5924
Important: varnish security update
RLSA-2023:5850
Important: nodejs:16 security update
RLSA-2023:5838
Important: nghttp2 security update
RLSA-2023:5765
Important: nodejs security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2021-06115 Уязвимость сервера приложений Apache Tomcat, связанная с утечкой памяти, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 11% Средний | почти 5 лет назад | |
GHSA-xjgh-84hx-56c5 Unrestricted Upload of File with Dangerous Type Apache Tomcat | CVSS3: 8.1 | 100% Критический | около 4 лет назад | |
CVE-2017-12617 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | CVSS3: 8.1 | 100% Критический | почти 9 лет назад | |
CVE-2017-12617 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | CVSS3: 8.1 | 100% Критический | почти 9 лет назад | |
CVE-2017-12617 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | CVSS3: 8.1 | 100% Критический | почти 9 лет назад | |
CVE-2017-12617 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22 ... | CVSS3: 8.1 | 100% Критический | почти 9 лет назад | |
BDU:2023-06559 Уязвимость реализации протокола HTTP/2, связанная с возможностью формирования потока запросов в рамках уже установленного сетевого соединения, без открытия новых сетевых соединений и без подтверждения получения пакетов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 100% Критический | почти 3 года назад | |
SUSE-SU-2023:4624-1 Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container | 100% Критический | больше 2 лет назад | ||
SUSE-SU-2023:4492-1 Security update for nghttp2 | 100% Критический | больше 2 лет назад | ||
SUSE-SU-2023:4295-1 Security update for nodejs10 | 100% Критический | больше 2 лет назад | ||
SUSE-SU-2023:4200-1 Security update for nghttp2 | 100% Критический | почти 3 года назад | ||
SUSE-SU-2023:4199-1 Security update for nghttp2 | 100% Критический | почти 3 года назад | ||
SUSE-SU-2023:4163-1 Security update for netty, netty-tcnative | 100% Критический | почти 3 года назад | ||
RLSA-2023:6120 Moderate: nginx:1.22 security update | 100% Критический | больше 2 лет назад | ||
RLSA-2023:5989 Important: varnish security update | 100% Критический | почти 3 года назад | ||
RLSA-2023:5928 Important: tomcat security update | 100% Критический | почти 3 года назад | ||
RLSA-2023:5924 Important: varnish security update | 100% Критический | почти 3 года назад | ||
RLSA-2023:5850 Important: nodejs:16 security update | 100% Критический | почти 3 года назад | ||
RLSA-2023:5838 Important: nghttp2 security update | 100% Критический | почти 3 года назад | ||
RLSA-2023:5765 Important: nodejs security update | 100% Критический | почти 3 года назад |
Уязвимостей на страницу