Логотип exploitDog
bind:"CVE-2014-0119"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2014-0119"

Количество 8

Количество 8

ubuntu логотип

CVE-2014-0119

почти 12 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0119

почти 12 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-0119

почти 12 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-0119

почти 12 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 d ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-prc3-7f44-w48j

почти 4 года назад

Missing XML Validation in Apache Tomcat

EPSS: Низкий
oracle-oval логотип

ELSA-2014-1034

больше 11 лет назад

ELSA-2014-1034: tomcat security update (LOW)

EPSS: Низкий
fstec логотип

BDU:2015-00409

почти 12 лет назад

Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

CVSS2: 4.3
EPSS: Низкий
oracle-oval логотип

ELSA-2014-1038

больше 11 лет назад

ELSA-2014-1038: tomcat6 security update (LOW)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-0119

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0119

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 2.1
4%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0119

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0119

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 d ...

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
github логотип
GHSA-prc3-7f44-w48j

Missing XML Validation in Apache Tomcat

4%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2014-1034

ELSA-2014-1034: tomcat security update (LOW)

больше 11 лет назад
fstec логотип
BDU:2015-00409

Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
oracle-oval логотип
ELSA-2014-1038

ELSA-2014-1038: tomcat6 security update (LOW)

больше 11 лет назад

Уязвимостей на страницу