Moderate severityNVD Advisory· Published Oct 4, 2002· Updated Apr 16, 2026
CVE-2002-0935
CVE-2002-0935
Description
Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | < 4.1.3-beta | 4.1.3-beta |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- www.iss.net/security_center/static/9396.phpnvdPatchVendor Advisory
- www.securityfocus.com/bid/5067nvdPatchVendor Advisory
- github.com/advisories/GHSA-xmf4-j3j7-xj7qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2002-0935ghsaADVISORY
- lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3EghsaWEB
- web.archive.org/web/20020822030311/http://www.iss.net/security_center/static/9396.phpghsaWEB
- web.archive.org/web/20021010182017/http://online.securityfocus.com/bid/5067ghsaWEB
- web.archive.org/web/20021116054924/http://online.securityfocus.com/archive/1/277940ghsaWEB
- web.archive.org/web/20070525180638/http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0120.htmlghsaWEB
- archives.neohapsis.com/archives/vulnwatch/2002-q2/0120.htmlnvd
- online.securityfocus.com/archive/1/277940nvd
- www.osvdb.org/5051nvd
- lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3Envd
News mentions
0No linked articles in our index yet.