Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache tomcat 4.1.10 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2002-1394
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148....
Apache Tomcat 4.0.3
Apache Tomcat 4.0.4
Apache Tomcat 4.0.5
Apache Tomcat 4.1.0
Apache Tomcat 4.0.0
Apache Tomcat 4.1.10
Apache Tomcat 4.1.3
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
Apache Tomcat 4.1.9
NA
CVE-2007-3383
Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and...
Apache Tomcat 4.0.3
Apache Tomcat 4.0.4
Apache Tomcat 4.1.2
Apache Tomcat 4.1.24
Apache Tomcat 4.0.5
Apache Tomcat 4.0.6
Apache Tomcat 4.1.28
Apache Tomcat 4.1.3
Apache Tomcat 4.1.31
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
Apache Tomcat 4.1.10
Apache Tomcat 4.1.15
Apache Tomcat 4.0.0
Apache Tomcat 4.1.0
Apache Tomcat 4.1.1
Apache Tomcat 4.1.36
NA
CVE-2002-1148
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet....
Apache Tomcat 3.0
Apache Tomcat 3.1
Apache Tomcat 3.3.1
Apache Tomcat 4.0.0
Apache Tomcat 4.1.3
Apache Tomcat 4.1.9
Apache Tomcat 3.2.1
Apache Tomcat 3.2.2
Apache Tomcat 3.2.3
Apache Tomcat 4.0.3
Apache Tomcat 4.0.4
Apache Tomcat 3.2.4
Apache Tomcat 3.3
Apache Tomcat 4.1.0
Apache Tomcat 4.1.10
Apache Tomcat 3.1.1
Apache Tomcat 3.2
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
1 EDB exploit available
NA
CVE-2008-3271
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite...
Apache Tomcat 4.1.15
Apache Tomcat 4.1.1
Apache Tomcat 4.1.21
Apache Tomcat 4.1.2
Apache Tomcat 4.1.29
Apache Tomcat 4.1.3
Apache Tomcat 4.1.8
Apache Tomcat 4.1.9
Apache Tomcat 4.1.11
Apache Tomcat 4.1.0
Apache Tomcat 4.1.16
Apache Tomcat 4.1.23
Apache Tomcat 4.1.24
Apache Tomcat 4.1.18
Apache Tomcat 4.1.26
Apache Tomcat 4.1.4
Apache Tomcat 4.1.5
Apache Tomcat 4.1.12
Apache Tomcat 4.1.10
Apache Tomcat 4.1.25
Apache Tomcat 4.1.20
Apache Tomcat 4.1.19
Apache Tomcat 4.1.30
Apache Tomcat 4.1.31
Apache Tomcat 5.5.0
Apache Tomcat 4.1.14
Apache Tomcat 4.1.13
Apache Tomcat 4.1.22
Apache Tomcat 4.1.17
Apache Tomcat 4.1.27
Apache Tomcat 4.1.28
Apache Tomcat 4.1.6
Apache Tomcat 4.1.7
NA
CVE-2007-5461
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity...
Apache Tomcat 4.0.3
Apache Tomcat 4.0.4
Apache Tomcat 4.1.14
Apache Tomcat 4.1.15
Apache Tomcat 4.1.21
Apache Tomcat 4.1.22
Apache Tomcat 4.1.29
Apache Tomcat 4.1.3
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
Apache Tomcat 4.0.0
Apache Tomcat 4.1.1
Apache Tomcat 4.1.10
Apache Tomcat 4.1.11
Apache Tomcat 4.1.18
Apache Tomcat 4.1.19
Apache Tomcat 4.1.25
Apache Tomcat 4.1.26
Apache Tomcat 4.1.33
Apache Tomcat 4.1.34
Apache Tomcat 4.1.8
Apache Tomcat 4.1.9
Apache Tomcat 4.0.5
Apache Tomcat 4.1.0
Apache Tomcat 4.1.16
Apache Tomcat 4.1.17
Apache Tomcat 4.1.23
Apache Tomcat 4.1.24
Apache Tomcat 4.1.30
Apache Tomcat 4.1.31
Apache Tomcat 4.1.32
Apache Tomcat 4.1.6
Apache Tomcat 4.1.7
Apache Tomcat 4.1.4
Apache Tomcat 4.1.5
Apache Tomcat 4.1.12
Apache Tomcat 4.1.13
Apache Tomcat 4.1.2
Apache Tomcat 4.1.20
Apache Tomcat 4.1.27
Apache Tomcat 4.1.28
Apache Tomcat 4.1.35
Apache Tomcat 4.1.36
Apache Tomcat 4.0.6
2 EDB exploits available
NA
CVE-2008-5515
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access...
Apache Tomcat 4.1.14
Apache Tomcat 4.1.15
Apache Tomcat 4.1.21
Apache Tomcat 4.1.22
Apache Tomcat 4.1.29
Apache Tomcat 4.1.3
Apache Tomcat 4.1.37
Apache Tomcat 4.1.38
Apache Tomcat 5.5.13
Apache Tomcat 5.5.14
Apache Tomcat 5.5.20
Apache Tomcat 5.5.21
Apache Tomcat 5.5.4
Apache Tomcat 5.5.5
Apache Tomcat 6.0.1
Apache Tomcat 6.0.10
Apache Tomcat 6.0.18
Apache Tomcat 6.0.2
Apache Tomcat 6.0.3
Apache Tomcat 4.1.0
Apache Tomcat 4.1.16
Apache Tomcat 4.1.17
Apache Tomcat 4.1.23
Apache Tomcat 4.1.24
Apache Tomcat 4.1.30
Apache Tomcat 4.1.31
Apache Tomcat 4.1.39
Apache Tomcat 5.5.0
Apache Tomcat 5.5.15
Apache Tomcat 5.5.16
Apache Tomcat 5.5.22
Apache Tomcat 5.5.23
Apache Tomcat 5.5.24
Apache Tomcat 5.5.6
Apache Tomcat 5.5.7
Apache Tomcat 6.0.12
Apache Tomcat 6.0.13
Apache Tomcat 6.0.4
Apache Tomcat 6.0.5
Apache Tomcat 4.1.1
Apache Tomcat 4.1.10
Apache Tomcat 4.1.11
Apache Tomcat 4.1.18
Apache Tomcat 4.1.19
Apache Tomcat 4.1.25
Apache Tomcat 4.1.26
Apache Tomcat 4.1.32
Apache Tomcat 4.1.33
Apache Tomcat 4.1.34
Apache Tomcat 5.5.1
Apache Tomcat 5.5.10
Apache Tomcat 5.5.17
Apache Tomcat 5.5.18
Apache Tomcat 5.5.25
Apache Tomcat 5.5.26
Apache Tomcat 5.5.8
Apache Tomcat 5.5.9
Apache Tomcat 6.0.14
Apache Tomcat 6.0.15
Apache Tomcat 6.0.6
Apache Tomcat 6.0.7
Apache Tomcat 4.1.12
Apache Tomcat 4.1.13
Apache Tomcat 4.1.2
Apache Tomcat 4.1.20
Apache Tomcat 4.1.27
Apache Tomcat 4.1.28
Apache Tomcat 4.1.35
Apache Tomcat 4.1.36
Apache Tomcat 5.5.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.19
Apache Tomcat 5.5.2
Apache Tomcat 5.5.27
Apache Tomcat 5.5.3
Apache Tomcat 6.0
Apache Tomcat 6.0.0
Apache Tomcat 6.0.16
Apache Tomcat 6.0.17
Apache Tomcat 6.0.9
NA
CVE-2007-1355
Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web...
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
Apache Tomcat 4.1.24
Apache Tomcat 4.1.28
Apache Tomcat 4.1.31
Apache Tomcat 5.0.15
Apache Tomcat 5.0.16
Apache Tomcat 5.0.23
Apache Tomcat 5.0.24
Apache Tomcat 5.0.4
Apache Tomcat 5.0.5
Apache Tomcat 6.0.10
Apache Tomcat 6.0.2
Apache Tomcat 6.0.9
Apache Tomcat 4.0.0
Apache Tomcat 4.1.10
Apache Tomcat 4.1.15
Apache Tomcat 5.0.13
Apache Tomcat 5.0.14
Apache Tomcat 5.0.21
Apache Tomcat 5.0.22
Apache Tomcat 5.0.29
Apache Tomcat 5.0.3
Apache Tomcat 5.0.30
Apache Tomcat 6.0.0
Apache Tomcat 6.0.1
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 4.0.3
Apache Tomcat 4.0.4
Apache Tomcat 5.0.1
Apache Tomcat 5.0.10
Apache Tomcat 5.0.17
Apache Tomcat 5.0.18
Apache Tomcat 5.0.25
Apache Tomcat 5.0.26
Apache Tomcat 5.0.6
Apache Tomcat 5.0.7
Apache Tomcat 6.0.3
Apache Tomcat 6.0.4
Apache Tomcat 4.0.5
Apache Tomcat 4.0.6
Apache Tomcat 5.0.11
Apache Tomcat 5.0.12
Apache Tomcat 5.0.19
Apache Tomcat 5.0.2
Apache Tomcat 5.0.27
Apache Tomcat 5.0.28
Apache Tomcat 5.0.8
Apache Tomcat 5.0.9
Apache Tomcat 6.0.5
Apache Tomcat 6.0.6
1 EDB exploit available
NA
CVE-2009-0033
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to...
Apache Tomcat 4.1.0
Apache Tomcat 4.1.1
Apache Tomcat 4.1.16
Apache Tomcat 4.1.17
Apache Tomcat 4.1.18
Apache Tomcat 4.1.24
Apache Tomcat 4.1.25
Apache Tomcat 4.1.30
Apache Tomcat 4.1.31
Apache Tomcat 4.1.5
Apache Tomcat 4.1.6
Apache Tomcat 5.5.10
Apache Tomcat 5.5.11
Apache Tomcat 5.5.18
Apache Tomcat 5.5.19
Apache Tomcat 5.5.26
Apache Tomcat 5.5.27
Apache Tomcat 5.5.9
Apache Tomcat 4.1.38
Apache Tomcat 6.0.4
Apache Tomcat 6.0.3
Apache Tomcat 6.0.8
Apache Tomcat 6.0.9
Apache Tomcat 4.1.10
Apache Tomcat 4.1.11
Apache Tomcat 4.1.19
Apache Tomcat 4.1.2
Apache Tomcat 4.1.26
Apache Tomcat 4.1.27
Apache Tomcat 4.1.32
Apache Tomcat 4.1.33
Apache Tomcat 4.1.7
Apache Tomcat 4.1.8
Apache Tomcat 5.5.12
Apache Tomcat 5.5.13
Apache Tomcat 5.5.2
Apache Tomcat 5.5.20
Apache Tomcat 5.5.3
Apache Tomcat 5.5.4
Apache Tomcat 4.1.39
Apache Tomcat 6.0.1
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.16
Apache Tomcat 4.1.14
Apache Tomcat 4.1.15
Apache Tomcat 4.1.22
Apache Tomcat 4.1.23
Apache Tomcat 4.1.3
Apache Tomcat 4.1.36
Apache Tomcat 4.1.37
Apache Tomcat 4.1.4
Apache Tomcat 5.5.0
Apache Tomcat 5.5.1
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.23
Apache Tomcat 5.5.24
Apache Tomcat 5.5.25
Apache Tomcat 5.5.7
Apache Tomcat 5.5.8
Apache Tomcat 6.0.14
Apache Tomcat 6.0.5
Apache Tomcat 6.0.6
Apache Tomcat 6.0.7
Apache Tomcat 4.1.12
Apache Tomcat 4.1.13
Apache Tomcat 4.1.20
Apache Tomcat 4.1.21
Apache Tomcat 4.1.28
Apache Tomcat 4.1.29
Apache Tomcat 4.1.34
Apache Tomcat 4.1.35
Apache Tomcat 4.1.9
Apache Tomcat 5.5.14
Apache Tomcat 5.5.15
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.5
Apache Tomcat 5.5.6
Apache Tomcat 6.0.0
Apache Tomcat 6.0.15
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.10
NA
CVE-2007-3385
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable...
Apache Tomcat 4.1.1
Apache Tomcat 4.1.10
Apache Tomcat 4.1.31
Apache Tomcat 4.1.36
Apache Tomcat 4.1.9
Apache Tomcat 5.0.14
Apache Tomcat 5.0.15
Apache Tomcat 5.0.22
Apache Tomcat 5.0.23
Apache Tomcat 5.0.30
Apache Tomcat 5.0.4
Apache Tomcat 5.5.1
Apache Tomcat 5.5.10
Apache Tomcat 5.5.17
Apache Tomcat 5.5.18
Apache Tomcat 5.5.3
Apache Tomcat 5.5.4
Apache Tomcat 6.0.1
Apache Tomcat 6.0.10
Apache Tomcat 6.0.5
Apache Tomcat 3.3
Apache Tomcat 4.1.15
Apache Tomcat 4.1.2
Apache Tomcat 5.0.0
Apache Tomcat 5.0.1
Apache Tomcat 5.0.16
Apache Tomcat 5.0.17
Apache Tomcat 5.0.24
Apache Tomcat 5.0.25
Apache Tomcat 5.0.5
Apache Tomcat 5.0.6
Apache Tomcat 5.5.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.19
Apache Tomcat 5.5.2
Apache Tomcat 5.5.5
Apache Tomcat 5.5.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.12
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 3.3.2
Apache Tomcat 4.1.0
Apache Tomcat 4.1.3
Apache Tomcat 5.0.12
Apache Tomcat 5.0.13
Apache Tomcat 5.0.2
Apache Tomcat 5.0.21
Apache Tomcat 5.0.28
Apache Tomcat 5.0.29
Apache Tomcat 5.0.3
Apache Tomcat 5.0.9
Apache Tomcat 5.5.0
Apache Tomcat 5.5.15
Apache Tomcat 5.5.16
Apache Tomcat 5.5.23
Apache Tomcat 5.5.24
Apache Tomcat 5.5.9
Apache Tomcat 6.0.0
Apache Tomcat 6.0.3
Apache Tomcat 3.3.1
Apache Tomcat 3.3.1a
Apache Tomcat 4.1.24
Apache Tomcat 4.1.28
Apache Tomcat 5.0.10
Apache Tomcat 5.0.11
Apache Tomcat 5.0.18
Apache Tomcat 5.0.19
Apache Tomcat 5.0.26
Apache Tomcat 5.0.27
Apache Tomcat 5.0.7
Apache Tomcat 5.0.8
Apache Tomcat 5.5.13
Apache Tomcat 5.5.14
Apache Tomcat 5.5.20
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.7
Apache Tomcat 5.5.8
Apache Tomcat 6.0.13
Apache Tomcat 6.0.2
Apache Tomcat 6.0.9
Apache Tomcat 6.0.4
Apache Tomcat 6.0.6
NA
CVE-2013-6357
** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as...
Apache Tomcat
Apache Tomcat 5.5.23
Apache Tomcat 5.5.19
Apache Tomcat 5.5.17
Apache Tomcat 5.5.10
Apache Tomcat 5.5.0
Apache Tomcat 5.0.30
Apache Tomcat 5.0.29
Apache Tomcat 5.0.24
Apache Tomcat 5.0.22
Apache Tomcat 5.0.15
Apache Tomcat 5.0.13
Apache Tomcat 4.1.9
Apache Tomcat 4.1.31
Apache Tomcat 4.1.24
Apache Tomcat 4.1.15
Apache Tomcat 4.0.4
Apache Tomcat 4.0.2
Apache Tomcat 3.3
Apache Tomcat 3.2.3
Apache Tomcat 3.1.1
Apache Tomcat 3.0
Apache Tomcat 5.5.3
Apache Tomcat 5.5.8
Apache Tomcat 5.5.22
Apache Tomcat 5.5.21
Apache Tomcat 5.5.20
Apache Tomcat 5.5.2
Apache Tomcat 5.0.8
Apache Tomcat 5.0.7
Apache Tomcat 5.0.6
Apache Tomcat 5.0.5
Apache Tomcat 5.0.2
Apache Tomcat 5.0.19
Apache Tomcat 5.0.18
Apache Tomcat 5.0.17
Apache Tomcat 5.0.16
Apache Tomcat 4.1.3
Apache Tomcat 4.1.29
Apache Tomcat 4.1.28
Apache Tomcat 4.0.0
Apache Tomcat 4
Apache Tomcat 3.3.2
Apache Tomcat 3.3.1a
Apache Tomcat 5.5.4
Apache Tomcat 5.5.5
Apache Tomcat 5.5.6
Apache Tomcat 5.5.7
Apache Tomcat 5.5.15
Apache Tomcat 5.5.14
Apache Tomcat 5.5.13
Apache Tomcat 5.5.12
Apache Tomcat 5.5.11
Apache Tomcat 5.0.28
Apache Tomcat 5.0.27
Apache Tomcat 5.0.26
Apache Tomcat 5.0.25
Apache Tomcat 5.0.11
Apache Tomcat 5.0.10
Apache Tomcat 5.0.1
Apache Tomcat 5.0.0
Apache Tomcat 4.1.10
Apache Tomcat 4.1.1
Apache Tomcat 4.1.0
Apache Tomcat 4.0.6
Apache Tomcat 4.0.5
Apache Tomcat 3.2.2
Apache Tomcat 3.2.1
Apache Tomcat 3.2
Apache Tomcat 5.5.24
Apache Tomcat 5.5.18
Apache Tomcat 5.5.16
Apache Tomcat 5.5.1
Apache Tomcat 5.0.9
Apache Tomcat 5.0.4
Apache Tomcat 5.0.3
Apache Tomcat 5.0.23
Apache Tomcat 5.0.21
Apache Tomcat 5.0.14
Apache Tomcat 5.0.12
Apache Tomcat 5
Apache Tomcat 4.1.36
Apache Tomcat 4.1.2
Apache Tomcat 4.1.12
Apache Tomcat 4.0.3
Apache Tomcat 4.0.1
Apache Tomcat 3.3.1
Apache Tomcat 3.2.4
Apache Tomcat 3.1
Apache Tomcat 1.1.3
Apache Tomcat 5.5.9
1 EDB exploit available
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-29436
NULL pointer dereference
CVE-2022-26925
CVE-2022-30947
overflow
CVE-2022-28192
CVE-2022-30072
remote
CVE-2022-30778
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »