Search CVE reports


Toggle filters

321 – 330 of 366 results


CVE-2008-3271

Medium priority
Ignored

Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread,...

3 affected packages

tomcat4, tomcat5, tomcat5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat4
tomcat5
tomcat5.5
Show less packages

CVE-2008-2938

Low priority

Some fixes available 2 of 4

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via...

2 affected packages

tomcat5.5, tomcat6

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5.5
tomcat6
Show less packages

CVE-2008-2370

Low priority

Some fixes available 2 of 4

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to...

2 affected packages

tomcat5.5, tomcat6

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5.5
tomcat6
Show less packages

CVE-2008-1232

Medium priority

Some fixes available 2 of 4

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the...

2 affected packages

tomcat5.5, tomcat6

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5.5
tomcat6
Show less packages

CVE-2008-1947

Medium priority

Some fixes available 1 of 5

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute)...

2 affected packages

tomcat5, tomcat5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5
tomcat5.5
Show less packages

CVE-2008-0002

Low priority
Not affected

Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated...

2 affected packages

tomcat5, tomcat5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5
tomcat5.5
Show less packages

CVE-2007-6286

Low priority
Ignored

Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy...

2 affected packages

tomcat5, tomcat5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5
tomcat5.5
Show less packages

CVE-2007-5333

Medium priority
Ignored

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive...

2 affected packages

tomcat5, tomcat5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5
tomcat5.5
Show less packages

CVE-2008-0128

Low priority
Ignored

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http...

2 affected packages

tomcat5, tomcat5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5
tomcat5.5
Show less packages

CVE-2007-5342

Low priority

Some fixes available 2 of 5

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify...

2 affected packages

tomcat5, tomcat5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5
tomcat5.5
Show less packages