Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 427

Количество 1 427

github логотип

GHSA-r6cf-cr44-m8rr

больше 4 лет назад

Apache Tomcat Leaks Pathname Information via Error Message

EPSS: Низкий
github логотип

GHSA-r29c-68gh-xp6x

3 месяца назад

Apache Tomcat - HTTP/2 request headers not validated

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-r22m-cc5w-vgh3

около 4 лет назад

** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator."

EPSS: Низкий
github логотип

GHSA-qvf5-hvjx-wm27

больше 1 года назад

Apache Tomcat Request and/or response mix-up

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qrj4-rmqg-4hcp

около 4 лет назад

Apache Tomcat Does Not Properly Handle Empty Requests

EPSS: Низкий
github логотип

GHSA-qrcx-p4rr-g48h

около 4 лет назад

Apache Tomcat allows remote attackers to read JSP source files

EPSS: Низкий
github логотип

GHSA-qqr5-q566-72w2

больше 4 лет назад

The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

EPSS: Средний
github логотип

GHSA-qq5r-98hh-rxc9

5 месяцев назад

Apache Tomcat - Security constraint bypass with HTTP/0.9

EPSS: Низкий
github логотип

GHSA-qprx-q2r7-3rx6

около 4 лет назад

Improper Input Validation in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-qjw9-54p2-cgcx

около 4 лет назад

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

EPSS: Средний
github логотип

GHSA-qg4g-6jcq-rw93

больше 4 лет назад

Jakarta Apache Tomcat Reveals Physical Paths

EPSS: Средний
github логотип

GHSA-qfxv-3ppc-7qg5

около 4 лет назад

Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions

EPSS: Средний
github логотип

GHSA-qfw2-wvrw-mvw4

больше 4 лет назад

Jakarta Tomcat Directory Listing vulnerability

EPSS: Средний
github логотип

GHSA-qff8-g48j-pwpw

около 4 лет назад

Apache Tomcat treats single quotes as delimiters in cookies

EPSS: Средний
github логотип

GHSA-qcxh-w3j9-58qr

около 6 лет назад

Apache Tomcat Denial of Service vulnerability

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-q9xf-jwr4-v445

около 4 лет назад

Authentication Bypass in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-q74x-qqhr-f8rx

около 4 лет назад

Apache Tomcat Cross-site scripting (XSS) vulnerability

EPSS: Высокий
github логотип

GHSA-q4hg-rmq2-52q9

около 7 лет назад

Improper Locking in Apache Tomcat

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-q3mw-pvr8-9ggc

почти 3 года назад

Apache Tomcat Open Redirect vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-pxwv-88pv-hh3j

около 4 лет назад

org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-r6cf-cr44-m8rr

Apache Tomcat Leaks Pathname Information via Error Message

7%
Низкий
больше 4 лет назад
github логотип
GHSA-r29c-68gh-xp6x

Apache Tomcat - HTTP/2 request headers not validated

CVSS3: 9.8
2%
Низкий
3 месяца назад
github логотип
GHSA-r22m-cc5w-vgh3

** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator."

2%
Низкий
около 4 лет назад
github логотип
GHSA-qvf5-hvjx-wm27

Apache Tomcat Request and/or response mix-up

CVSS3: 6.5
2%
Низкий
больше 1 года назад
github логотип
GHSA-qrj4-rmqg-4hcp

Apache Tomcat Does Not Properly Handle Empty Requests

5%
Низкий
около 4 лет назад
github логотип
GHSA-qrcx-p4rr-g48h

Apache Tomcat allows remote attackers to read JSP source files

3%
Низкий
около 4 лет назад
github логотип
GHSA-qqr5-q566-72w2

The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

62%
Средний
больше 4 лет назад
github логотип
GHSA-qq5r-98hh-rxc9

Apache Tomcat - Security constraint bypass with HTTP/0.9

0%
Низкий
5 месяцев назад
github логотип
GHSA-qprx-q2r7-3rx6

Improper Input Validation in Apache Tomcat

7%
Низкий
около 4 лет назад
github логотип
GHSA-qjw9-54p2-cgcx

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

20%
Средний
около 4 лет назад
github логотип
GHSA-qg4g-6jcq-rw93

Jakarta Apache Tomcat Reveals Physical Paths

26%
Средний
больше 4 лет назад
github логотип
GHSA-qfxv-3ppc-7qg5

Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions

11%
Средний
около 4 лет назад
github логотип
GHSA-qfw2-wvrw-mvw4

Jakarta Tomcat Directory Listing vulnerability

46%
Средний
больше 4 лет назад
github логотип
GHSA-qff8-g48j-pwpw

Apache Tomcat treats single quotes as delimiters in cookies

37%
Средний
около 4 лет назад
github логотип
GHSA-qcxh-w3j9-58qr

Apache Tomcat Denial of Service vulnerability

CVSS3: 7.5
73%
Высокий
около 6 лет назад
github логотип
GHSA-q9xf-jwr4-v445

Authentication Bypass in Apache Tomcat

9%
Низкий
около 4 лет назад
github логотип
GHSA-q74x-qqhr-f8rx

Apache Tomcat Cross-site scripting (XSS) vulnerability

76%
Высокий
около 4 лет назад
github логотип
GHSA-q4hg-rmq2-52q9

Improper Locking in Apache Tomcat

CVSS3: 7.5
73%
Высокий
около 7 лет назад
github логотип
GHSA-q3mw-pvr8-9ggc

Apache Tomcat Open Redirect vulnerability

CVSS3: 6.1
6%
Низкий
почти 3 года назад
github логотип
GHSA-pxwv-88pv-hh3j

org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.

7%
Низкий
около 4 лет назад

Уязвимостей на страницу