Количество 1 427
Количество 1 427
GHSA-wc4r-xq3c-5cf3
Apache Tomcat - Security constraint bypass for pre/post-resources
GHSA-w97x-xfxf-f9xj
Jakarta Tomcat Denial of Service vulnerability
GHSA-w7cg-5969-678w
Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token
GHSA-w6q7-ww2x-7gm3
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
GHSA-w65j-cmqc-37p2
JULI logging component in Apache Tomcat does not restrict certain permissions for web applications
GHSA-w3j5-q8f2-3cqq
Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat
GHSA-w227-xcfx-3pj8
Exposure of Sensitive Information in Apache Tomcat
GHSA-vfww-5hm6-hx2j
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
GHSA-vch7-92vf-jm44
Apache Tomcat does not follow ServletSecurity annotations
GHSA-v682-8vv8-vpwr
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
GHSA-v66v-63h2-8q5q
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
GHSA-v5p2-vg3c-pmrr
Apache Tomcat Path Traversal Vulnerability
GHSA-v35g-wxj7-gxp3
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
GHSA-rv64-5gf8-9qq8
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
GHSA-rq2w-37h9-vg94
Apache Tomcat improperly escapes input from JsonErrorReportValve
GHSA-rp8h-vr48-4j8p
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
GHSA-rh8q-vjgf-gf74
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
GHSA-rffr-vjp4-vxh3
The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
GHSA-r7c8-hghc-2mp8
Apache Tomcat Allows Replacing of XML Parser
GHSA-r6j3-px5g-cq3x
Apache Tomcat Improper Input Validation vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-wc4r-xq3c-5cf3 Apache Tomcat - Security constraint bypass for pre/post-resources | 3% Низкий | около 1 года назад | ||
GHSA-w97x-xfxf-f9xj Jakarta Tomcat Denial of Service vulnerability | 2% Низкий | больше 4 лет назад | ||
GHSA-w7cg-5969-678w Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token | CVSS3: 8.8 | 9% Низкий | около 4 лет назад | |
GHSA-w6q7-ww2x-7gm3 Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat | 53% Средний | около 4 лет назад | ||
GHSA-w65j-cmqc-37p2 JULI logging component in Apache Tomcat does not restrict certain permissions for web applications | 5% Низкий | около 4 лет назад | ||
GHSA-w3j5-q8f2-3cqq Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat | CVSS3: 7.5 | 16% Средний | около 4 лет назад | |
GHSA-w227-xcfx-3pj8 Exposure of Sensitive Information in Apache Tomcat | 94% Критический | около 4 лет назад | ||
GHSA-vfww-5hm6-hx2j Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences | CVSS3: 9.6 | 10% Средний | 9 месяцев назад | |
GHSA-vch7-92vf-jm44 Apache Tomcat does not follow ServletSecurity annotations | 7% Низкий | около 4 лет назад | ||
GHSA-v682-8vv8-vpwr Denial of Service via incomplete cleanup vulnerability in Apache Tomcat | CVSS3: 6.3 | 2% Низкий | больше 2 лет назад | |
GHSA-v66v-63h2-8q5q Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action. | 59% Средний | около 4 лет назад | ||
GHSA-v5p2-vg3c-pmrr Apache Tomcat Path Traversal Vulnerability | 40% Средний | около 4 лет назад | ||
GHSA-v35g-wxj7-gxp3 Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris. | 10% Низкий | около 4 лет назад | ||
GHSA-rv64-5gf8-9qq8 Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-rq2w-37h9-vg94 Apache Tomcat improperly escapes input from JsonErrorReportValve | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
GHSA-rp8h-vr48-4j8p Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests | 7% Низкий | около 4 лет назад | ||
GHSA-rh8q-vjgf-gf74 Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat | CVSS3: 5.3 | 18% Средний | около 4 лет назад | |
GHSA-rffr-vjp4-vxh3 The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN. | 4% Низкий | больше 4 лет назад | ||
GHSA-r7c8-hghc-2mp8 Apache Tomcat Allows Replacing of XML Parser | 1% Низкий | около 4 лет назад | ||
GHSA-r6j3-px5g-cq3x Apache Tomcat Improper Input Validation vulnerability | CVSS3: 5.3 | 6% Низкий | почти 3 года назад |
Уязвимостей на страницу