Search CVE reports


Toggle filters

61 – 70 of 123 results


CVE-2015-5345

Low priority

Some fixes available 6 of 9

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
tomcat9 Fixed
Show less packages

CVE-2015-5174

Low priority

Some fixes available 4 of 7

Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-7810

Medium priority

Some fixes available 7 of 12

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class,...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-0230

Low priority

Some fixes available 4 of 9

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a...

3 affected packages

tomcat7, tomcat8, tomcat6

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat7 Not affected
tomcat8 Not affected
tomcat6 Not in release
Show less packages

CVE-2014-0227

Low priority

Some fixes available 4 of 9

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred,...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-0119

Low priority

Some fixes available 2 of 7

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files...

3 affected packages

tomcat8, tomcat6, tomcat7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat8 Not in release Not affected
tomcat6 Not in release Not in release
tomcat7 Not in release Not affected
Show less packages

CVE-2014-0099

Medium priority

Some fixes available 4 of 7

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-0096

Medium priority

Some fixes available 4 of 7

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-0075

Medium priority

Some fixes available 4 of 7

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remote attackers to cause a denial...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2013-4590

Low priority
Ignored

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx,...

2 affected packages

tomcat6, tomcat7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release
tomcat7 Not in release Not affected
Show less packages