Search CVE reports


Toggle filters

81 – 90 of 125 results


CVE-2015-5174

Low priority

Some fixes available 4 of 7

Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-7810

Medium priority

Some fixes available 7 of 12

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class,...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-0230

Low priority

Some fixes available 4 of 9

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a...

3 affected packages

tomcat7, tomcat8, tomcat6

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat7 Not affected
tomcat8 Not affected
tomcat6 Not in release
Show less packages

CVE-2014-0227

Low priority

Some fixes available 4 of 9

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred,...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2013-4444

Medium priority
Ignored

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading...

1 affected package

tomcat7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat7
Show less packages

CVE-2014-0186

Medium priority
Not affected

A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL) 7 allows remote attackers to cause a denial of service (CPU consumption) via a crafted request. NOTE: this vulnerability exists because of an...

1 affected package

tomcat7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat7
Show less packages

CVE-2014-0119

Low priority

Some fixes available 2 of 7

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files...

3 affected packages

tomcat8, tomcat6, tomcat7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat8 Not in release Not affected
tomcat6 Not in release Not in release
tomcat7 Not in release Not affected
Show less packages

CVE-2014-0099

Medium priority

Some fixes available 4 of 7

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-0096

Medium priority

Some fixes available 4 of 7

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages

CVE-2014-0075

Medium priority

Some fixes available 4 of 7

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remote attackers to cause a denial...

3 affected packages

tomcat6, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release
tomcat7 Not affected
tomcat8 Not affected
Show less packages