CVE-2021-33037
- EPSS 75.35%
- Veröffentlicht 12.07.2021 15:15:08
- Zuletzt bearbeitet 25.08.2026 16:28:27
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specific...
- EPSS 9.49%
- Veröffentlicht 01.03.2021 12:15:14
- Zuletzt bearbeitet 25.08.2026 16:28:27
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnera...
CVE-2021-25122
- EPSS 18.11%
- Veröffentlicht 01.03.2021 12:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and use...
CVE-2020-13935
- EPSS 86.61%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with inv...
CVE-2020-13934
- EPSS 64.12%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException co...
- EPSS 56.64%
- Veröffentlicht 20.05.2020 19:15:09
- Zuletzt bearbeitet 25.08.2026 16:28:27
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the Persiste...
CVE-2019-10219
- EPSS 2.17%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-17359
- EPSS 8.95%
- Veröffentlicht 08.10.2019 14:15:10
- Zuletzt bearbeitet 12.05.2025 17:37:16
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
CVE-2019-2538
- EPSS 1.14%
- Veröffentlicht 16.01.2019 19:30:35
- Zuletzt bearbeitet 21.11.2024 04:41:04
Vulnerability in the Oracle Managed File Transfer component of Oracle Fusion Middleware (subcomponent: MFT Runtime Server). Supported versions that are affected are 19.1.0.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged att...
CVE-2018-1000613
- EPSS 4.77%
- Veröffentlicht 09.07.2018 20:29:00
- Zuletzt bearbeitet 12.05.2025 17:37:16
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT priv...