Bug | Description |
---|
TEMP-0840685-CEF76B | TOCTOU race condition in initscript on chown'ing JVM_TMP temporary directory |
CVE-2021-25329 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10. ... |
CVE-2021-25122 | When responding to new h2c connection requests, Apache Tomcat versions ... |
CVE-2021-24122 | When serving resources from a network location using the NTFS file sys ... |
CVE-2020-17527 | While investigating bug 64830 it was discovered that Apache Tomcat 10. ... |
CVE-2020-13943 | If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7 ... |
CVE-2020-13935 | The payload length in a WebSocket frame was not correctly validated in ... |
CVE-2020-13934 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0. ... |
CVE-2020-11996 | A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat ... |
CVE-2020-9484 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to ... |
CVE-2020-1938 | When using the Apache JServ Protocol (AJP), care must be taken when tr ... |
CVE-2020-1935 | In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0. ... |
CVE-2019-17569 | The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8 ... |
CVE-2019-17563 | When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, ... |
CVE-2019-12418 | When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0. ... |
CVE-2019-10072 | The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 co ... |
CVE-2019-0232 | When running on Windows with enableCmdLineArguments enabled, the CGI S ... |
CVE-2019-0221 | The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 ... |
CVE-2019-0199 | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5. ... |
CVE-2018-11784 | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, ... |
CVE-2018-8037 | If an async request was completed by the application at the same time ... |
CVE-2018-8034 | The host name verification when using TLS with the WebSocket client wa ... |
CVE-2018-8014 | The defaults settings for the CORS filter provided in Apache Tomcat 9. ... |
CVE-2018-1336 | An improper handing of overflow in the UTF-8 decoder with supplementar ... |
CVE-2018-1305 | Security constraints defined by annotations of Servlets in Apache Tomc ... |
CVE-2018-1304 | The URL pattern of "" (the empty string) which exactly maps to the con ... |
CVE-2017-15706 | As part of the fix for bug 61201, the documentation for Apache Tomcat ... |
CVE-2017-12617 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22 ... |
CVE-2017-7675 | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8 ... |
CVE-2017-7674 | The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.1 ... |
CVE-2017-6056 | It was discovered that a programming error in the processing of HTTPS ... |
CVE-2017-5664 | The error page mechanism of the Java Servlet Specification requires th ... |
CVE-2017-5651 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refact ... |
CVE-2017-5650 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handli ... |
CVE-2017-5648 | While investigating bug 60718, it was noticed that some calls to appli ... |
CVE-2017-5647 | A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0 ... |
CVE-2016-9775 | The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 o ... |
CVE-2016-9774 | The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 ... |
CVE-2016-8747 | An information disclosure issue was discovered in Apache Tomcat 8.5.7 ... |
CVE-2016-8745 | A bug in the error handling of the send file code for the NIO HTTP con ... |
CVE-2016-8735 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7. ... |
CVE-2016-6817 | The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8. ... |
CVE-2016-6816 | The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0 ... |
CVE-2016-6797 | The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9. ... |
CVE-2016-6796 | A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0 ... |
CVE-2016-6794 | When a SecurityManager is configured, a web application's ability to r ... |
CVE-2016-6325 | The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBo ... |
CVE-2016-5425 | The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentO ... |
CVE-2016-5388 | Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI S ... |
CVE-2016-5018 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8. ... |
CVE-2016-3092 | The MultipartStream class in Apache Commons Fileupload before 1.3.2, a ... |
CVE-2016-1240 | The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 a ... |
CVE-2016-0763 | The setGlobalContext method in org/apache/naming/factory/ResourceLinkF ... |
CVE-2016-0762 | The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0. ... |
CVE-2016-0714 | The session-persistence implementation in Apache Tomcat 6.x before 6.0 ... |
CVE-2016-0706 | Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, ... |
CVE-2015-5351 | The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x ... |
CVE-2015-5346 | Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x ... |
CVE-2015-5345 | The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7. ... |
CVE-2015-5174 | Directory traversal vulnerability in RequestUtil.java in Apache Tomcat ... |
CVE-2014-7810 | The Expression Language (EL) implementation in Apache Tomcat 6.x befor ... |
CVE-2014-0230 | Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0 ... |
CVE-2014-0227 | java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apach ... |
CVE-2014-0119 | Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 d ... |
CVE-2014-0099 | Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apac ... |
CVE-2014-0096 | java/org/apache/catalina/servlets/DefaultServlet.java in the default s ... |
CVE-2014-0095 | java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat ... |
CVE-2014-0075 | Integer overflow in the parseChunkHeader function in java/org/apache/c ... |
CVE-2013-4590 | Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-R ... |
CVE-2013-4322 | Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-R ... |
CVE-2013-4286 | Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-R ... |