CVE-2016-0702
- EPSS 0.46%
- Veröffentlicht 03.03.2016 20:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discov...
- EPSS 21.84%
- Veröffentlicht 03.03.2016 20:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other imp...
CVE-2016-0763
- EPSS 0.29%
- Veröffentlicht 25.02.2016 01:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, wh...
CVE-2016-0714
- EPSS 10.16%
- Veröffentlicht 25.02.2016 01:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restric...
CVE-2016-0706
- EPSS 1.54%
- Veröffentlicht 25.02.2016 01:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote aut...
CVE-2015-5351
- EPSS 2.31%
- Veröffentlicht 25.02.2016 01:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protec...
CVE-2015-5346
- EPSS 36.17%
- Veröffentlicht 25.02.2016 01:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to ...
CVE-2015-5345
- EPSS 49.88%
- Veröffentlicht 25.02.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence o...
CVE-2015-5174
- EPSS 4.8%
- Veröffentlicht 25.02.2016 01:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.....
CVE-2013-7448
- EPSS 0.55%
- Veröffentlicht 23.02.2016 19:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in wiki.c in didiwiki allows remote attackers to read arbitrary files via the page parameter to api/page/get.