Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache tomcat 4.1.31 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2007-4724
Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters....
Apache Tomcat 4.1.31
4.3
CVSSv2
CVE-2007-3383
Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and...
Apache Tomcat 4.0.3
Apache Tomcat 4.0.4
Apache Tomcat 4.1.2
Apache Tomcat 4.1.24
Apache Tomcat 4.0.5
Apache Tomcat 4.0.6
Apache Tomcat 4.1.28
Apache Tomcat 4.1.3
Apache Tomcat 4.1.31
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
Apache Tomcat 4.1.10
Apache Tomcat 4.1.15
Apache Tomcat 4.0.0
Apache Tomcat 4.1.0
Apache Tomcat 4.1.1
Apache Tomcat 4.1.36
4.3
CVSSv2
CVE-2008-3271
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite...
Apache Tomcat 4.1.15
Apache Tomcat 4.1.1
Apache Tomcat 4.1.21
Apache Tomcat 4.1.2
Apache Tomcat 4.1.29
Apache Tomcat 4.1.3
Apache Tomcat 4.1.8
Apache Tomcat 4.1.9
Apache Tomcat 4.1.11
Apache Tomcat 4.1.0
Apache Tomcat 4.1.16
Apache Tomcat 4.1.23
Apache Tomcat 4.1.24
Apache Tomcat 4.1.18
Apache Tomcat 4.1.26
Apache Tomcat 4.1.4
Apache Tomcat 4.1.5
Apache Tomcat 4.1.12
Apache Tomcat 4.1.10
Apache Tomcat 4.1.25
Apache Tomcat 4.1.20
Apache Tomcat 4.1.19
Apache Tomcat 4.1.30
Apache Tomcat 4.1.31
Apache Tomcat 5.5.0
Apache Tomcat 4.1.14
Apache Tomcat 4.1.13
Apache Tomcat 4.1.22
Apache Tomcat 4.1.17
Apache Tomcat 4.1.27
Apache Tomcat 4.1.28
Apache Tomcat 4.1.6
Apache Tomcat 4.1.7
7.8
CVSSv2
CVE-2005-4836
The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information....
Apache Tomcat 4.1.17
Apache Tomcat 4.1.18
Apache Tomcat 4.1.26
Apache Tomcat 4.1.27
Apache Tomcat 4.1.33
Apache Tomcat 4.1.34
Apache Tomcat 4.1.15
Apache Tomcat 4.1.16
Apache Tomcat 4.1.24
Apache Tomcat 4.1.25
Apache Tomcat 4.1.31
Apache Tomcat 4.1.32
Apache Tomcat 4.1.40
Apache Tomcat 4.1.21
Apache Tomcat 4.1.22
Apache Tomcat 4.1.23
Apache Tomcat 4.1.29
Apache Tomcat 4.1.30
Apache Tomcat 4.1.37
Apache Tomcat 4.1.39
Apache Tomcat 4.1.19
Apache Tomcat 4.1.20
Apache Tomcat 4.1.28
Apache Tomcat 4.1.35
Apache Tomcat 4.1.36
3.5
CVSSv2
CVE-2007-5461
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity...
Apache Tomcat 4.0.3
Apache Tomcat 4.0.4
Apache Tomcat 4.1.14
Apache Tomcat 4.1.15
Apache Tomcat 4.1.21
Apache Tomcat 4.1.22
Apache Tomcat 4.1.29
Apache Tomcat 4.1.3
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
Apache Tomcat 4.0.0
Apache Tomcat 4.1.1
Apache Tomcat 4.1.10
Apache Tomcat 4.1.11
Apache Tomcat 4.1.18
Apache Tomcat 4.1.19
Apache Tomcat 4.1.25
Apache Tomcat 4.1.26
Apache Tomcat 4.1.33
Apache Tomcat 4.1.34
Apache Tomcat 4.1.8
Apache Tomcat 4.1.9
Apache Tomcat 4.0.5
Apache Tomcat 4.1.0
Apache Tomcat 4.1.16
Apache Tomcat 4.1.17
Apache Tomcat 4.1.23
Apache Tomcat 4.1.24
Apache Tomcat 4.1.30
Apache Tomcat 4.1.31
Apache Tomcat 4.1.32
Apache Tomcat 4.1.6
Apache Tomcat 4.1.7
Apache Tomcat 4.1.4
Apache Tomcat 4.1.5
Apache Tomcat 4.1.12
Apache Tomcat 4.1.13
Apache Tomcat 4.1.2
Apache Tomcat 4.1.20
Apache Tomcat 4.1.27
Apache Tomcat 4.1.28
Apache Tomcat 4.1.35
Apache Tomcat 4.1.36
Apache Tomcat 4.0.6
2 EDB exploits available
2.6
CVSSv2
CVE-2007-1858
The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified...
Apache Tomcat 4.1.28
Apache Tomcat 4.1.31
Apache Tomcat 5.0.14
Apache Tomcat 5.0.15
Apache Tomcat 5.0.22
Apache Tomcat 5.0.23
Apache Tomcat 5.0.30
Apache Tomcat 5.5.0
Apache Tomcat 5.5.1
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.8
Apache Tomcat 5.5.9
Apache Tomcat 5.0.12
Apache Tomcat 5.0.13
Apache Tomcat 5.0.2
Apache Tomcat 5.0.21
Apache Tomcat 5.0.28
Apache Tomcat 5.0.29
Apache Tomcat 5.5.14
Apache Tomcat 5.5.15
Apache Tomcat 5.5.6
Apache Tomcat 5.5.7
Apache Tomcat 5.0.10
Apache Tomcat 5.0.11
Apache Tomcat 5.0.18
Apache Tomcat 5.0.19
Apache Tomcat 5.0.26
Apache Tomcat 5.0.27
Apache Tomcat 5.5.12
Apache Tomcat 5.5.13
Apache Tomcat 5.5.4
Apache Tomcat 5.5.5
Apache Tomcat 5.0.0
Apache Tomcat 5.0.1
Apache Tomcat 5.0.16
Apache Tomcat 5.0.17
Apache Tomcat 5.0.24
Apache Tomcat 5.0.25
Apache Tomcat 5.5.10
Apache Tomcat 5.5.11
Apache Tomcat 5.5.2
Apache Tomcat 5.5.3
12 Github repositories available
4.3
CVSSv2
CVE-2007-1355
Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web...
Apache Tomcat 4.0.1
Apache Tomcat 4.0.2
Apache Tomcat 4.1.24
Apache Tomcat 4.1.28
Apache Tomcat 4.1.31
Apache Tomcat 5.0.15
Apache Tomcat 5.0.16
Apache Tomcat 5.0.23
Apache Tomcat 5.0.24
Apache Tomcat 5.0.4
Apache Tomcat 5.0.5
Apache Tomcat 6.0.10
Apache Tomcat 6.0.2
Apache Tomcat 6.0.9
Apache Tomcat 4.0.0
Apache Tomcat 4.1.10
Apache Tomcat 4.1.15
Apache Tomcat 5.0.13
Apache Tomcat 5.0.14
Apache Tomcat 5.0.21
Apache Tomcat 5.0.22
Apache Tomcat 5.0.29
Apache Tomcat 5.0.3
Apache Tomcat 5.0.30
Apache Tomcat 6.0.0
Apache Tomcat 6.0.1
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 4.0.3
Apache Tomcat 4.0.4
Apache Tomcat 5.0.1
Apache Tomcat 5.0.10
Apache Tomcat 5.0.17
Apache Tomcat 5.0.18
Apache Tomcat 5.0.25
Apache Tomcat 5.0.26
Apache Tomcat 5.0.6
Apache Tomcat 5.0.7
Apache Tomcat 6.0.3
Apache Tomcat 6.0.4
Apache Tomcat 4.0.5
Apache Tomcat 4.0.6
Apache Tomcat 5.0.11
Apache Tomcat 5.0.12
Apache Tomcat 5.0.19
Apache Tomcat 5.0.2
Apache Tomcat 5.0.27
Apache Tomcat 5.0.28
Apache Tomcat 5.0.8
Apache Tomcat 5.0.9
Apache Tomcat 6.0.5
Apache Tomcat 6.0.6
1 EDB exploit available
4.3
CVSSv2
CVE-2006-7196
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to...
Apache Tomcat 4.0.0
Apache Tomcat 4.0.1
Apache Tomcat 5.0.1
Apache Tomcat 5.0.10
Apache Tomcat 5.0.18
Apache Tomcat 5.0.19
Apache Tomcat 5.0.26
Apache Tomcat 5.0.27
Apache Tomcat 5.0.6
Apache Tomcat 5.0.7
Apache Tomcat 5.0.8
Apache Tomcat 5.5.13
Apache Tomcat 5.5.14
Apache Tomcat 5.5.7
Apache Tomcat 5.5.8
Apache Tomcat 4.0.2
Apache Tomcat 4.0.3
Apache Tomcat 5.0.11
Apache Tomcat 5.0.12
Apache Tomcat 5.0.13
Apache Tomcat 5.0.2
Apache Tomcat 5.0.21
Apache Tomcat 5.0.28
Apache Tomcat 5.0.29
Apache Tomcat 5.0.9
Apache Tomcat 5.5.0
Apache Tomcat 5.5.15
Apache Tomcat 5.5.2
Apache Tomcat 5.5.9
Apache Tomcat
Apache Tomcat 4.0.6
Apache Tomcat 5.0.0
Apache Tomcat 5.0.16
Apache Tomcat 5.0.17
Apache Tomcat 5.0.24
Apache Tomcat 5.0.25
Apache Tomcat 5.0.4
Apache Tomcat 5.0.5
Apache Tomcat 5.5.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.5
Apache Tomcat 5.5.6
Apache Tomcat 4.0.4
Apache Tomcat 4.0.5
Apache Tomcat 5.0.14
Apache Tomcat 5.0.15
Apache Tomcat 5.0.22
Apache Tomcat 5.0.23
Apache Tomcat 5.0.3
Apache Tomcat 5.0.30
Apache Tomcat 5.5.1
Apache Tomcat 5.5.10
Apache Tomcat 5.5.3
Apache Tomcat 5.5.4
1 EDB exploit available
5
CVSSv2
CVE-2009-0033
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to...
Apache Tomcat 4.1.0
Apache Tomcat 4.1.1
Apache Tomcat 4.1.16
Apache Tomcat 4.1.17
Apache Tomcat 4.1.18
Apache Tomcat 4.1.24
Apache Tomcat 4.1.25
Apache Tomcat 4.1.30
Apache Tomcat 4.1.31
Apache Tomcat 4.1.5
Apache Tomcat 4.1.6
Apache Tomcat 5.5.10
Apache Tomcat 5.5.11
Apache Tomcat 5.5.18
Apache Tomcat 5.5.19
Apache Tomcat 5.5.26
Apache Tomcat 5.5.27
Apache Tomcat 5.5.9
Apache Tomcat 4.1.38
Apache Tomcat 6.0.4
Apache Tomcat 6.0.3
Apache Tomcat 6.0.8
Apache Tomcat 6.0.9
Apache Tomcat 4.1.10
Apache Tomcat 4.1.11
Apache Tomcat 4.1.19
Apache Tomcat 4.1.2
Apache Tomcat 4.1.26
Apache Tomcat 4.1.27
Apache Tomcat 4.1.32
Apache Tomcat 4.1.33
Apache Tomcat 4.1.7
Apache Tomcat 4.1.8
Apache Tomcat 5.5.12
Apache Tomcat 5.5.13
Apache Tomcat 5.5.2
Apache Tomcat 5.5.20
Apache Tomcat 5.5.3
Apache Tomcat 5.5.4
Apache Tomcat 4.1.39
Apache Tomcat 6.0.1
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.16
Apache Tomcat 4.1.14
Apache Tomcat 4.1.15
Apache Tomcat 4.1.22
Apache Tomcat 4.1.23
Apache Tomcat 4.1.3
Apache Tomcat 4.1.36
Apache Tomcat 4.1.37
Apache Tomcat 4.1.4
Apache Tomcat 5.5.0
Apache Tomcat 5.5.1
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.23
Apache Tomcat 5.5.24
Apache Tomcat 5.5.25
Apache Tomcat 5.5.7
Apache Tomcat 5.5.8
Apache Tomcat 6.0.14
Apache Tomcat 6.0.5
Apache Tomcat 6.0.6
Apache Tomcat 6.0.7
Apache Tomcat 4.1.12
Apache Tomcat 4.1.13
Apache Tomcat 4.1.20
Apache Tomcat 4.1.21
Apache Tomcat 4.1.28
Apache Tomcat 4.1.29
Apache Tomcat 4.1.34
Apache Tomcat 4.1.35
Apache Tomcat 4.1.9
Apache Tomcat 5.5.14
Apache Tomcat 5.5.15
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.5
Apache Tomcat 5.5.6
Apache Tomcat 6.0.0
Apache Tomcat 6.0.15
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.10
4.3
CVSSv2
CVE-2007-3385
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable...
Apache Tomcat 4.1.1
Apache Tomcat 4.1.10
Apache Tomcat 4.1.31
Apache Tomcat 4.1.36
Apache Tomcat 4.1.9
Apache Tomcat 5.0.14
Apache Tomcat 5.0.15
Apache Tomcat 5.0.22
Apache Tomcat 5.0.23
Apache Tomcat 5.0.30
Apache Tomcat 5.0.4
Apache Tomcat 5.5.1
Apache Tomcat 5.5.10
Apache Tomcat 5.5.17
Apache Tomcat 5.5.18
Apache Tomcat 5.5.3
Apache Tomcat 5.5.4
Apache Tomcat 6.0.1
Apache Tomcat 6.0.10
Apache Tomcat 6.0.5
Apache Tomcat 3.3
Apache Tomcat 4.1.15
Apache Tomcat 4.1.2
Apache Tomcat 5.0.0
Apache Tomcat 5.0.1
Apache Tomcat 5.0.16
Apache Tomcat 5.0.17
Apache Tomcat 5.0.24
Apache Tomcat 5.0.25
Apache Tomcat 5.0.5
Apache Tomcat 5.0.6
Apache Tomcat 5.5.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.19
Apache Tomcat 5.5.2
Apache Tomcat 5.5.5
Apache Tomcat 5.5.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.12
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 3.3.2
Apache Tomcat 4.1.0
Apache Tomcat 4.1.3
Apache Tomcat 5.0.12
Apache Tomcat 5.0.13
Apache Tomcat 5.0.2
Apache Tomcat 5.0.21
Apache Tomcat 5.0.28
Apache Tomcat 5.0.29
Apache Tomcat 5.0.3
Apache Tomcat 5.0.9
Apache Tomcat 5.5.0
Apache Tomcat 5.5.15
Apache Tomcat 5.5.16
Apache Tomcat 5.5.23
Apache Tomcat 5.5.24
Apache Tomcat 5.5.9
Apache Tomcat 6.0.0
Apache Tomcat 6.0.3
Apache Tomcat 3.3.1
Apache Tomcat 3.3.1a
Apache Tomcat 4.1.24
Apache Tomcat 4.1.28
Apache Tomcat 5.0.10
Apache Tomcat 5.0.11
Apache Tomcat 5.0.18
Apache Tomcat 5.0.19
Apache Tomcat 5.0.26
Apache Tomcat 5.0.27
Apache Tomcat 5.0.7
Apache Tomcat 5.0.8
Apache Tomcat 5.5.13
Apache Tomcat 5.5.14
Apache Tomcat 5.5.20
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.7
Apache Tomcat 5.5.8
Apache Tomcat 6.0.13
Apache Tomcat 6.0.2
Apache Tomcat 6.0.9
Apache Tomcat 6.0.4
Apache Tomcat 6.0.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
stored XSS
CVE-2022-29582
CVE-2020-6507
CVE-2022-36835
CVE-2022-24028
CVE-2022-2692
CVE-2022-26346
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »