CVE-2014-0050
- EPSS 92.71%
- Veröffentlicht 01.04.2014 06:27:51
- Zuletzt bearbeitet 06.05.2026 22:30:45
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that b...
CVE-2013-4286
- EPSS 23.6%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identifi...
CVE-2013-4322
- EPSS 36.66%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field...
CVE-2013-4590
- EPSS 0.92%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML d...
CVE-2014-0033
- EPSS 16.23%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a cra...
CVE-2013-0346
- EPSS 0.64%
- Veröffentlicht 15.02.2014 14:57:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain...
CVE-2013-2185
- EPSS 5.29%
- Veröffentlicht 19.01.2014 18:02:57
- Zuletzt bearbeitet 29.04.2026 01:13:23
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a fi...
CVE-2013-6357
- EPSS 1%
- Veröffentlicht 13.11.2013 15:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST met...
- EPSS 44.77%
- Veröffentlicht 01.06.2013 14:21:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
CVE-2013-2067
- EPSS 10.45%
- Veröffentlicht 01.06.2013 14:21:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions,...