VYPR

Tomcat

by Apache

Source repositories

CVEs (269)

  • CVE-2005-4836Dec 31, 2005
    risk 0.00cvss epss 0.03

    The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

  • CVE-2005-3510Nov 6, 2005
    risk 0.00cvss epss 0.06

    Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

  • CVE-2003-0045Feb 7, 2003
    risk 0.00cvss epss 0.02

    Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.

  • CVE-2003-0043Feb 7, 2003
    risk 0.00cvss epss 0.05

    Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.

  • CVE-2002-1394Jan 17, 2003
    risk 0.00cvss epss 0.06

    Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

  • CVE-2002-1895Dec 31, 2002
    risk 0.00cvss epss 0.04

    The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.

  • CVE-2002-0493Aug 12, 2002
    risk 0.00cvss epss 0.04

    Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.

  • CVE-2000-1210Mar 22, 2002
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.

  • CVE-2001-1563Dec 31, 2001
    risk 0.00cvss epss 0.05

    Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

Page 14 of 14