Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 466

Количество 1 466

debian логотип

CVE-2013-4286

больше 12 лет назад

Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-R ...

CVSS2: 5.8
EPSS: Средний
ubuntu логотип

CVE-2013-2071

около 13 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2013-2071

около 13 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-2071

около 13 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2013-2071

около 13 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7 ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2013-2067

около 13 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2013-2067

около 13 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-2067

около 13 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-2067

около 13 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the f ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-0346

больше 12 лет назад

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2013-0346

больше 13 лет назад

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0346

больше 12 лет назад

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2013-0346

больше 12 лет назад

Apache Tomcat 7.x uses world-readable permissions for the log director ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2012-5887

больше 13 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2012-5887

больше 13 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2012-5887

больше 13 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2012-5887

больше 13 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2012-5886

больше 13 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5886

больше 13 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-5886

больше 13 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2013-4286

Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-R ...

CVSS2: 5.8
17%
Средний
больше 12 лет назад
ubuntu логотип
CVE-2013-2071

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
7%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2071

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
7%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2071

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
7%
Низкий
около 13 лет назад
debian логотип
CVE-2013-2071

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7 ...

CVSS2: 2.6
7%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2013-2067

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS2: 6.8
7%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2067

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS2: 2.6
7%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2067

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS2: 6.8
7%
Низкий
около 13 лет назад
debian логотип
CVE-2013-2067

java/org/apache/catalina/authenticator/FormAuthenticator.java in the f ...

CVSS2: 6.8
7%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2013-0346

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

CVSS2: 2.1
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-0346

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

CVSS2: 2.1
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0346

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

CVSS2: 2.1
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-0346

Apache Tomcat 7.x uses world-readable permissions for the log director ...

CVSS2: 2.1
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-5887

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

CVSS2: 5
12%
Средний
больше 13 лет назад
redhat логотип
CVE-2012-5887

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

CVSS2: 5
12%
Средний
больше 13 лет назад
nvd логотип
CVE-2012-5887

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

CVSS2: 5
12%
Средний
больше 13 лет назад
debian логотип
CVE-2012-5887

The HTTP Digest Access Authentication implementation in Apache Tomcat ...

CVSS2: 5
12%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-5886

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.

CVSS2: 5
9%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5886

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.

CVSS2: 5
9%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5886

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.

CVSS2: 5
9%
Низкий
больше 13 лет назад

Уязвимостей на страницу