Количество 1 155
Количество 1 155
GHSA-qprx-q2r7-3rx6
Improper Input Validation in Apache Tomcat
GHSA-qjw9-54p2-cgcx
The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
GHSA-qg4g-6jcq-rw93
Jakarta Apache Tomcat Reveals Physical Paths
GHSA-qfxv-3ppc-7qg5
Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions
GHSA-qfw2-wvrw-mvw4
Jakarta Tomcat Directory Listing vulnerability
GHSA-qff8-g48j-pwpw
Apache Tomcat treats single quotes as delimiters in cookies
GHSA-qcxh-w3j9-58qr
Apache Tomcat Denial of Service vulnerability
GHSA-q9xf-jwr4-v445
Authentication Bypass in Apache Tomcat
GHSA-q74x-qqhr-f8rx
Apache Tomcat Cross-site scripting (XSS) vulnerability
GHSA-q4hg-rmq2-52q9
Improper Locking in Apache Tomcat
GHSA-q3mw-pvr8-9ggc
Apache Tomcat Open Redirect vulnerability
GHSA-pxwv-88pv-hh3j
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
GHSA-pvjh-7h8q-q56r
Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header
GHSA-prc3-7f44-w48j
Missing XML Validation in Apache Tomcat
GHSA-ppj6-9ppm-3h56
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).
GHSA-pm78-wxxf-fw98
Cross-site scripting in Apache Tomcat
GHSA-p57v-p3fx-qgwm
Apache Tomcat XSS Vulnerability
GHSA-p543-jg43-9pm5
Apache Tomcat may be started without proper security settings
GHSA-p26v-97vp-jcx6
Access controll bypass in Apache Tomcat
GHSA-p263-rh6r-g7jw
Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-qprx-q2r7-3rx6 Improper Input Validation in Apache Tomcat | 2% Низкий | больше 3 лет назад | ||
GHSA-qjw9-54p2-cgcx The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 3% Низкий | больше 3 лет назад | ||
GHSA-qg4g-6jcq-rw93 Jakarta Apache Tomcat Reveals Physical Paths | 40% Средний | больше 3 лет назад | ||
GHSA-qfxv-3ppc-7qg5 Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions | 38% Средний | больше 3 лет назад | ||
GHSA-qfw2-wvrw-mvw4 Jakarta Tomcat Directory Listing vulnerability | 56% Средний | больше 3 лет назад | ||
GHSA-qff8-g48j-pwpw Apache Tomcat treats single quotes as delimiters in cookies | 86% Высокий | больше 3 лет назад | ||
GHSA-qcxh-w3j9-58qr Apache Tomcat Denial of Service vulnerability | CVSS3: 7.5 | 67% Средний | больше 5 лет назад | |
GHSA-q9xf-jwr4-v445 Authentication Bypass in Apache Tomcat | 5% Низкий | больше 3 лет назад | ||
GHSA-q74x-qqhr-f8rx Apache Tomcat Cross-site scripting (XSS) vulnerability | 38% Средний | больше 3 лет назад | ||
GHSA-q4hg-rmq2-52q9 Improper Locking in Apache Tomcat | CVSS3: 7.5 | 76% Высокий | около 6 лет назад | |
GHSA-q3mw-pvr8-9ggc Apache Tomcat Open Redirect vulnerability | CVSS3: 6.1 | 11% Средний | около 2 лет назад | |
GHSA-pxwv-88pv-hh3j org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response. | 23% Средний | больше 3 лет назад | ||
GHSA-pvjh-7h8q-q56r Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header | 2% Низкий | больше 3 лет назад | ||
GHSA-prc3-7f44-w48j Missing XML Validation in Apache Tomcat | 5% Низкий | больше 3 лет назад | ||
GHSA-ppj6-9ppm-3h56 The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). | 8% Низкий | больше 3 лет назад | ||
GHSA-pm78-wxxf-fw98 Cross-site scripting in Apache Tomcat | 77% Высокий | больше 3 лет назад | ||
GHSA-p57v-p3fx-qgwm Apache Tomcat XSS Vulnerability | 15% Средний | больше 3 лет назад | ||
GHSA-p543-jg43-9pm5 Apache Tomcat may be started without proper security settings | 1% Низкий | больше 3 лет назад | ||
GHSA-p26v-97vp-jcx6 Access controll bypass in Apache Tomcat | 1% Низкий | больше 3 лет назад | ||
GHSA-p263-rh6r-g7jw Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers. | 5% Низкий | больше 3 лет назад |
Уязвимостей на страницу