Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache tomcat 4.0.4 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2002-1895
The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN....
Apache Tomcat 4.0.4
Apache Tomcat 3.3
NA
CVE-2007-1358
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616"....
Apache Tomcat 4.0.4
Apache Tomcat 4.0.6
Apache Tomcat 4.0.3
Apache Tomcat 4.0.1
Apache Tomcat 4.1.0
Apache Tomcat 4.0.2
Apache Tomcat 4.0.5
Apache Tomcat 4.0.0
Apache Tomcat
NA
CVE-2003-0866
The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests....
Apache Tomcat 4.0.4
Apache Tomcat 4.0.6
Apache Tomcat 4.0.3
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
Apache Tomcat 4.0.5
Apache Tomcat 4.0.0
1 EDB exploit available
NA
CVE-2002-1394
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148....
Apache Tomcat 4.0.4
Apache Tomcat 4.1.9
Apache Tomcat 4.0.3
Apache Tomcat 4.0.1
Apache Tomcat 4.1.3
Apache Tomcat 4.1.10
Apache Tomcat 4.1.0
Apache Tomcat 4.0.2
Apache Tomcat 4.0.5
Apache Tomcat 4.0.0
NA
CVE-2007-3383
Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and...
Apache Tomcat 4.1.2
Apache Tomcat 4.0.4
Apache Tomcat 4.1.36
Apache Tomcat 4.1.24
Apache Tomcat 4.1.31
Apache Tomcat 4.0.6
Apache Tomcat 4.0.3
Apache Tomcat 4.0.1
Apache Tomcat 4.1.1
Apache Tomcat 4.1.28
Apache Tomcat 4.1.15
Apache Tomcat 4.1.10
Apache Tomcat 4.1.0
Apache Tomcat 4.0.2
Apache Tomcat 4.1.3
Apache Tomcat 4.0.5
Apache Tomcat 4.0.0
NA
CVE-2002-1148
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet....
Apache Tomcat 3.1
Apache Tomcat 4.0.4
Apache Tomcat 3.2.1
Apache Tomcat 4.1.9
Apache Tomcat 3.2.2
Apache Tomcat 3.2.4
Apache Tomcat 3.0
Apache Tomcat 4.0.3
Apache Tomcat 4.0.1
Apache Tomcat 4.1.3
Apache Tomcat 4.1.10
Apache Tomcat 4.1.0
Apache Tomcat 3.1.1
Apache Tomcat 4.0.2
Apache Tomcat 4.0.0
Apache Tomcat 3.2.3
Apache Tomcat 3.2
Apache Tomcat 3.3.1
Apache Tomcat 3.3
1 EDB exploit available
NA
CVE-2007-2449
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary...
Apache Tomcat 4.0.4
Apache Tomcat 5.5.18
Apache Tomcat 5.0.8
Apache Tomcat 5.0.19
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 5.5.12
Apache Tomcat 5.0.14
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.0.22
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.0.7
Apache Tomcat 6.0.7
Apache Tomcat 5.5.11
Apache Tomcat 6.0.4
Apache Tomcat 5.5.6
Apache Tomcat 5.0.9
Apache Tomcat 5.0.15
Apache Tomcat 5.0.30
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.0.23
Apache Tomcat 5.0.2
Apache Tomcat 5.5.5
Apache Tomcat 5.0.10
Apache Tomcat 5.0.21
Apache Tomcat 5.0.26
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 6.0.10
Apache Tomcat 6.0.3
Apache Tomcat 5.0.0
Apache Tomcat 5.0.6
Apache Tomcat 5.5.3
Apache Tomcat 5.0.27
Apache Tomcat 5.0.16
Apache Tomcat 5.5.9
Apache Tomcat 4.0.3
Apache Tomcat 5.0.18
Apache Tomcat 6.0.0
Apache Tomcat 4.0.1
Apache Tomcat 5.5.2
Apache Tomcat 5.0.5
Apache Tomcat 5.0.28
Apache Tomcat 5.0.29
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 5.0.13
Apache Tomcat
Apache Tomcat 5.5.8
Apache Tomcat 5.0.17
Apache Tomcat 5.5.16
Apache Tomcat 6.0.5
Apache Tomcat 4.0.2
Apache Tomcat 5.5.17
Apache Tomcat 5.5.19
Apache Tomcat 4.0.5
Apache Tomcat 4.0.0
Apache Tomcat 5.0.4
Apache Tomcat 6.0.2
Apache Tomcat 5.0.25
Apache Tomcat 6.0.13
Apache Tomcat 5.0.1
Apache Tomcat 5.0.11
Apache Tomcat 5.0.3
Apache Tomcat 5.0.24
Apache Tomcat 6.0.8
Apache Tomcat 5.0.12
1 EDB exploit available
NA
CVE-2006-7196
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to...
Apache Tomcat 4.0.4
Apache Tomcat 5.0.8
Apache Tomcat 5.0.19
Apache Tomcat 5.5.12
Apache Tomcat 5.0.14
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.0.22
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.0.7
Apache Tomcat 5.5.11
Apache Tomcat 5.5.6
Apache Tomcat 5.0.9
Apache Tomcat 5.0.15
Apache Tomcat 5.0.30
Apache Tomcat 5.5.15
Apache Tomcat 5.0.23
Apache Tomcat 5.0.2
Apache Tomcat 5.5.5
Apache Tomcat 5.0.10
Apache Tomcat 5.0.21
Apache Tomcat 5.0.26
Apache Tomcat 5.0.0
Apache Tomcat 5.0.6
Apache Tomcat 5.5.3
Apache Tomcat 5.0.27
Apache Tomcat 5.0.16
Apache Tomcat 4.0.6
Apache Tomcat 5.5.9
Apache Tomcat 4.0.3
Apache Tomcat 5.0.18
Apache Tomcat 4.0.1
Apache Tomcat 5.5.2
Apache Tomcat 5.0.5
Apache Tomcat 5.0.28
Apache Tomcat 5.0.29
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 5.0.13
Apache Tomcat 5.5.8
Apache Tomcat 5.0.17
Apache Tomcat 4.0.2
Apache Tomcat 4.0.5
Apache Tomcat 4.0.0
Apache Tomcat 5.0.4
Apache Tomcat 5.0.25
Apache Tomcat 5.0.1
Apache Tomcat 5.0.11
Apache Tomcat 5.0.3
Apache Tomcat
Apache Tomcat 5.0.24
Apache Tomcat 5.0.12
1 EDB exploit available
NA
CVE-2007-5461
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity...
Apache Tomcat 4.1.2
Apache Tomcat 4.0.4
Apache Tomcat 4.1.35
Apache Tomcat 4.1.36
Apache Tomcat 4.1.21
Apache Tomcat 4.1.24
Apache Tomcat 4.1.25
Apache Tomcat 4.1.4
Apache Tomcat 4.1.27
Apache Tomcat 4.1.30
Apache Tomcat 4.1.7
Apache Tomcat 4.1.11
Apache Tomcat 4.1.18
Apache Tomcat 4.1.14
Apache Tomcat 4.1.19
Apache Tomcat 4.1.31
Apache Tomcat 4.1.16
Apache Tomcat 4.1.29
Apache Tomcat 4.1.22
Apache Tomcat 4.0.6
Apache Tomcat 4.1.5
Apache Tomcat 4.1.26
Apache Tomcat 4.1.13
Apache Tomcat 4.1.8
Apache Tomcat 4.0.3
Apache Tomcat 4.1.17
Apache Tomcat 4.0.1
Apache Tomcat 4.1.33
Apache Tomcat 4.1.1
Apache Tomcat 4.1.12
Apache Tomcat 4.1.28
Apache Tomcat 4.1.15
Apache Tomcat 4.1.10
Apache Tomcat 4.1.0
Apache Tomcat 4.1.20
Apache Tomcat 4.0.2
Apache Tomcat 4.1.3
Apache Tomcat 4.0.5
Apache Tomcat 4.1.23
Apache Tomcat 4.0.0
Apache Tomcat 4.1.34
Apache Tomcat 4.1.32
Apache Tomcat 4.1.6
Apache Tomcat 4.1.9
2 EDB exploits available
NA
CVE-2013-6357
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a...
Apache Tomcat 3.1
Apache Tomcat 4.1.2
Apache Tomcat 4.0.4
Apache Tomcat 4.1.36
Apache Tomcat 3.2.1
Apache Tomcat 4.1.9
Apache Tomcat 5.5.18
Apache Tomcat 5.0.8
Apache Tomcat 5
Apache Tomcat
Apache Tomcat 5.0.19
Apache Tomcat 5.5.12
Apache Tomcat 5.0.14
Apache Tomcat 5.5.14
Apache Tomcat 4.1.24
Apache Tomcat 3.2.2
Apache Tomcat 5.5.10
Apache Tomcat 5.0.22
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.0.7
Apache Tomcat 5.5.11
Apache Tomcat 5.5.6
Apache Tomcat 5.0.9
Apache Tomcat 5.0.15
Apache Tomcat 3.3.2
Apache Tomcat 5.0.30
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.0.23
Apache Tomcat 1.1.3
Apache Tomcat 3.2.4
Apache Tomcat 5.0.2
Apache Tomcat 5.5.5
Apache Tomcat 5.0.10
Apache Tomcat 5.0.21
Apache Tomcat 3.0
Apache Tomcat 5.0.26
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.0.0
Apache Tomcat 5.0.6
Apache Tomcat 4.1.31
Apache Tomcat 5.5.3
Apache Tomcat 5.0.27
Apache Tomcat 4.1.29
Apache Tomcat 5.0.16
Apache Tomcat 4.0.6
Apache Tomcat 5.5.9
Apache Tomcat 4.0.3
Apache Tomcat 5.0.18
Apache Tomcat 4.0.1
Apache Tomcat 3.3.1a
Apache Tomcat 5.5.2
Apache Tomcat 5.0.5
Apache Tomcat 5.0.28
Apache Tomcat 5.0.29
Apache Tomcat 5.5.0
Apache Tomcat 4.1.1
Apache Tomcat 5.5.13
Apache Tomcat 5.5.24
Apache Tomcat 4.1.12
Apache Tomcat 4.1.28
Apache Tomcat 5.0.13
Apache Tomcat 4.1.15
Apache Tomcat 4.1.3
Apache Tomcat 4.1.10
Apache Tomcat 5.5.8
Apache Tomcat 5.0.17
Apache Tomcat 5.5.16
Apache Tomcat 4.1.0
Apache Tomcat 3.1.1
Apache Tomcat 4.0.2
Apache Tomcat 5.5.17
Apache Tomcat 5.5.19
Apache Tomcat 4.0.5
Apache Tomcat 4.0.0
Apache Tomcat 4
Apache Tomcat 5.0.4
Apache Tomcat 3.2.3
Apache Tomcat 5.0.25
Apache Tomcat 5.0.1
Apache Tomcat 3.2
Apache Tomcat 3.3.1
Apache Tomcat 5.0.11
Apache Tomcat 5.5.23
Apache Tomcat 5.0.3
Apache Tomcat 5.0.24
Apache Tomcat 3.3
Apache Tomcat 5.0.12
1 EDB exploit available
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-4518
malicious code
validation
CVE-2023-42916
template injection
CVE-2023-41266
CVE-2023-43089
CVE-2023-5995
CVE-2023-21746
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »