VYPR

Maven package

org.apache.tomcat.embed/tomcat-embed-core

pkg:maven/org.apache.tomcat.embed/tomcat-embed-core

Vulnerabilities (64)

  • CVE-2017-5651CriApr 17, 2017
    affected >= 9.0.0.M1, < 9.0.0.M19fixed 9.0.0.M19

    In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This

  • CVE-2017-5648CriApr 17, 2017
    affected >= 9.0.0.M1, < 9.0.0.M18fixed 9.0.0.M18

    While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a Securi

  • CVE-2014-0095May 31, 2014
    affected >= 8.0.0-RC1, < 8.0.4fixed 8.0.4

    java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.

  • CVE-2008-1947Jun 4, 2008
    affected >= 5.5.9, < 5.5.27fixed 5.5.27

    Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

Page 4 of 4