CVE-2013-4286
- EPSS 26.07%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identifi...
CVE-2013-4322
- EPSS 70.7%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field...
CVE-2013-4590
- EPSS 0.22%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML d...
CVE-2014-0033
- EPSS 15.13%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a cra...
CVE-2013-0346
- EPSS 0.49%
- Veröffentlicht 15.02.2014 14:57:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain...
CVE-2013-2185
- EPSS 5.29%
- Veröffentlicht 19.01.2014 18:02:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a fi...
CVE-2013-6357
- EPSS 1.26%
- Veröffentlicht 13.11.2013 15:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST met...
- EPSS 51.02%
- Veröffentlicht 01.06.2013 14:21:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
CVE-2013-2067
- EPSS 4.25%
- Veröffentlicht 01.06.2013 14:21:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions,...
CVE-2013-2071
- EPSS 6.87%
- Veröffentlicht 01.06.2013 14:21:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive req...