Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache tomcat 6.0 vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv2
CVE-2016-1240
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before...
Apache Tomcat 6.0
Apache Tomcat 7.0
Apache Tomcat 8.0
1 EDB exploit available
6 Github repositories available
6.4
CVSSv2
CVE-2007-5342
The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as...
Apache Tomcat 5.5.18
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 6.0.7
Apache Tomcat 5.5.11
Apache Tomcat 6.0.4
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 6.0.15
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 6.0.10
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 6.0.14
Apache Tomcat 5.5.13
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 5.5.24
Apache Tomcat 5.5.16
Apache Tomcat 6.0.5
Apache Tomcat 5.5.17
Apache Tomcat 5.5.19
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 5.5.23
Apache Tomcat 6.0.8
6.4
CVSSv2
CVE-2010-4312
The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie....
Apache Tomcat 6.0.15
Apache Tomcat 6.0
Apache Tomcat 6.0.28
Apache Tomcat 6.0.17
Apache Tomcat 6.0.18
Apache Tomcat 6.0.2
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.14
Apache Tomcat 6.0.6
Apache Tomcat 6.0.1
Apache Tomcat 6.0.0
Apache Tomcat 6.0.13
Apache Tomcat 6.0.24
Apache Tomcat 6.0.9
Apache Tomcat 6.0.29
Apache Tomcat 6.0.4
Apache Tomcat 6.0.3
Apache Tomcat 6.0.10
Apache Tomcat 6.0.20
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 6.0.5
Apache Tomcat 6.0.27
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
2.6
CVSSv2
CVE-2012-4534
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during...
Apache Tomcat 6.0.15
Apache Tomcat 6.0.8
Apache Tomcat 6.0.9
Apache Tomcat 6.0.33
Apache Tomcat 6.0.14
Apache Tomcat 6.0.6
Apache Tomcat 6.0.7
Apache Tomcat 6.0.29
Apache Tomcat 6.0.2
Apache Tomcat 6.0.1
Apache Tomcat 6.0.27
Apache Tomcat 6.0.3
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.4
Apache Tomcat 6.0.0
Apache Tomcat 6.0.32
Apache Tomcat 6.0.13
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.17
Apache Tomcat 6.0.18
Apache Tomcat 6.0.26
Apache Tomcat 6.0.10
Apache Tomcat 6.0.20
Apache Tomcat 6.0.30
Apache Tomcat 6.0
Apache Tomcat 6.0.35
Apache Tomcat 6.0.28
Apache Tomcat 6.0.5
Apache Tomcat 6.0.24
Apache Tomcat 6.0.31
Apache Tomcat 7.0.5
Apache Tomcat 7.0.6
Apache Tomcat 7.0.21
Apache Tomcat 7.0.17
Apache Tomcat 7.0.14
Apache Tomcat 7.0.3
Apache Tomcat 7.0.12
Apache Tomcat 7.0.8
Apache Tomcat 7.0.23
Apache Tomcat 7.0.2
Apache Tomcat 7.0.0
Apache Tomcat 7.0.16
Apache Tomcat 7.0.7
Apache Tomcat 7.0.18
Apache Tomcat 7.0.15
Apache Tomcat 7.0.10
Apache Tomcat 7.0.11
Apache Tomcat 7.0.4
Apache Tomcat 7.0.25
Apache Tomcat 7.0.13
Apache Tomcat 7.0.1
Apache Tomcat 7.0.20
Apache Tomcat 7.0.19
Apache Tomcat 7.0.22
Apache Tomcat 7.0.9
5
CVSSv2
CVE-2011-5062
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a...
Apache Tomcat 5.5.30
Apache Tomcat 5.5.0
Apache Tomcat 5.5.8
Apache Tomcat 5.5.33
Apache Tomcat 5.5.18
Apache Tomcat 5.5.15
Apache Tomcat 5.5.3
Apache Tomcat 5.5.22
Apache Tomcat 5.5.2
Apache Tomcat 5.5.1
Apache Tomcat 5.5.28
Apache Tomcat 5.5.4
Apache Tomcat 5.5.29
Apache Tomcat 5.5.14
Apache Tomcat 5.5.11
Apache Tomcat 5.5.32
Apache Tomcat 5.5.20
Apache Tomcat 5.5.27
Apache Tomcat 5.5.9
Apache Tomcat 5.5.31
Apache Tomcat 5.5.17
Apache Tomcat 5.5.12
Apache Tomcat 5.5.24
Apache Tomcat 5.5.21
Apache Tomcat 5.5.19
Apache Tomcat 5.5.25
Apache Tomcat 5.5.10
Apache Tomcat 5.5.7
Apache Tomcat 5.5.6
Apache Tomcat 5.5.5
Apache Tomcat 5.5.16
Apache Tomcat 5.5.13
Apache Tomcat 5.5.23
Apache Tomcat 5.5.26
Apache Tomcat 6.0.15
Apache Tomcat 6.0.9
Apache Tomcat 6.0.29
Apache Tomcat 6.0.4
Apache Tomcat 6.0.27
Apache Tomcat 6.0.31
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.14
Apache Tomcat 6.0.6
Apache Tomcat 6.0.18
Apache Tomcat 6.0.1
Apache Tomcat 6.0.2
Apache Tomcat 6.0.32
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 6.0.0
Apache Tomcat 6.0.5
Apache Tomcat 6.0.24
Apache Tomcat 6.0.13
Apache Tomcat 6.0.30
Apache Tomcat 6.0
Apache Tomcat 6.0.28
Apache Tomcat 6.0.17
Apache Tomcat 6.0.3
Apache Tomcat 6.0.26
Apache Tomcat 6.0.10
Apache Tomcat 6.0.20
Apache Tomcat 7.0.6
Apache Tomcat 7.0.1
Apache Tomcat 7.0.3
Apache Tomcat 7.0.7
Apache Tomcat 7.0.2
Apache Tomcat 7.0.0
Apache Tomcat 7.0.5
Apache Tomcat 7.0.4
Apache Tomcat 7.0.10
Apache Tomcat 7.0.11
Apache Tomcat 7.0.9
Apache Tomcat 7.0.8
4.3
CVSSv2
CVE-2011-5064
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass...
Apache Tomcat 5.5.10
Apache Tomcat 5.5.1
Apache Tomcat 5.5.6
Apache Tomcat 5.5.5
Apache Tomcat 5.5.16
Apache Tomcat 5.5.13
Apache Tomcat 5.5.26
Apache Tomcat 5.5.32
Apache Tomcat 5.5.28
Apache Tomcat 5.5.27
Apache Tomcat 5.5.4
Apache Tomcat 5.5.29
Apache Tomcat 5.5.14
Apache Tomcat 5.5.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.20
Apache Tomcat 5.5.21
Apache Tomcat 5.5.0
Apache Tomcat 5.5.25
Apache Tomcat 5.5.33
Apache Tomcat 5.5.7
Apache Tomcat 5.5.18
Apache Tomcat 5.5.15
Apache Tomcat 5.5.22
Apache Tomcat 5.5.23
Apache Tomcat 5.5.30
Apache Tomcat 5.5.9
Apache Tomcat 5.5.8
Apache Tomcat 5.5.31
Apache Tomcat 5.5.17
Apache Tomcat 5.5.24
Apache Tomcat 5.5.3
Apache Tomcat 5.5.19
Apache Tomcat 5.5.2
Apache Tomcat 6.0.30
Apache Tomcat 6.0
Apache Tomcat 6.0.28
Apache Tomcat 6.0.17
Apache Tomcat 6.0.18
Apache Tomcat 6.0.14
Apache Tomcat 6.0.6
Apache Tomcat 6.0.1
Apache Tomcat 6.0.0
Apache Tomcat 6.0.32
Apache Tomcat 6.0.24
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.15
Apache Tomcat 6.0.9
Apache Tomcat 6.0.29
Apache Tomcat 6.0.27
Apache Tomcat 6.0.3
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.26
Apache Tomcat 6.0.2
Apache Tomcat 6.0.10
Apache Tomcat 6.0.20
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 6.0.5
Apache Tomcat 6.0.4
Apache Tomcat 6.0.13
Apache Tomcat 6.0.31
Apache Tomcat 7.0.0
Apache Tomcat 7.0.4
Apache Tomcat 7.0.6
Apache Tomcat 7.0.1
Apache Tomcat 7.0.10
Apache Tomcat 7.0.7
Apache Tomcat 7.0.9
Apache Tomcat 7.0.11
Apache Tomcat 7.0.2
Apache Tomcat 7.0.8
Apache Tomcat 7.0.5
Apache Tomcat 7.0.3
4.3
CVSSv2
CVE-2011-0013
Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag....
Apache Tomcat 7.0.1
Apache Tomcat 7.0.2
Apache Tomcat 7.0.5
Apache Tomcat 7.0.0
Apache Tomcat 7.0.4
Apache Tomcat 7.0.3
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.7
Apache Tomcat 6.0.4
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.29
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0.24
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 6.0.28
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.5
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.27
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 5.5.30
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.3
Apache Tomcat 5.5.31
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 5.5.24
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.29
Apache Tomcat 5.5.19
Apache Tomcat 5.5.23
4.3
CVSSv2
CVE-2012-3546
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at...
Apache Tomcat 6.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.29
Apache Tomcat 6.0.33
Apache Tomcat 6.0.18
Apache Tomcat 6.0.1
Apache Tomcat 6.0.32
Apache Tomcat 6.0.9
Apache Tomcat 6.0.8
Apache Tomcat 6.0.2
Apache Tomcat 6.0.4
Apache Tomcat 6.0.27
Apache Tomcat 6.0.3
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.6
Apache Tomcat 6.0.7
Apache Tomcat 6.0.28
Apache Tomcat 6.0.0
Apache Tomcat 6.0.5
Apache Tomcat 6.0.24
Apache Tomcat 6.0.31
Apache Tomcat 6.0.13
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.15
Apache Tomcat 6.0.30
Apache Tomcat 6.0.35
Apache Tomcat 6.0.17
Apache Tomcat 6.0.26
Apache Tomcat 6.0.10
Apache Tomcat 6.0.20
Apache Tomcat 7.0.5
Apache Tomcat 7.0.6
Apache Tomcat 7.0.17
Apache Tomcat 7.0.14
Apache Tomcat 7.0.3
Apache Tomcat 7.0.28
Apache Tomcat 7.0.22
Apache Tomcat 7.0.9
Apache Tomcat 7.0.13
Apache Tomcat 7.0.2
Apache Tomcat 7.0.1
Apache Tomcat 7.0.20
Apache Tomcat 7.0.4
Apache Tomcat 7.0.0
Apache Tomcat 7.0.7
Apache Tomcat 7.0.19
Apache Tomcat 7.0.15
Apache Tomcat 7.0.23
Apache Tomcat 7.0.25
Apache Tomcat 7.0.16
Apache Tomcat 7.0.21
Apache Tomcat 7.0.18
Apache Tomcat 7.0.10
Apache Tomcat 7.0.11
Apache Tomcat 7.0.12
Apache Tomcat 7.0.8
5
CVSSv2
CVE-2012-2733
java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a...
Apache Tomcat 6.0.6
Apache Tomcat 6.0.7
Apache Tomcat 6.0.17
Apache Tomcat 6.0.0
Apache Tomcat 6.0.2
Apache Tomcat 6.0.26
Apache Tomcat 6.0.10
Apache Tomcat 6.0.20
Apache Tomcat 6.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.29
Apache Tomcat 6.0.1
Apache Tomcat 6.0.27
Apache Tomcat 6.0.3
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.9
Apache Tomcat 6.0.8
Apache Tomcat 6.0.33
Apache Tomcat 6.0.4
Apache Tomcat 6.0.18
Apache Tomcat 6.0.32
Apache Tomcat 6.0.13
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.15
Apache Tomcat 6.0.30
Apache Tomcat 6.0.28
Apache Tomcat 6.0.5
Apache Tomcat 6.0.24
Apache Tomcat 6.0.31
Apache Tomcat 6.0.35
Apache Tomcat 7.0.6
Apache Tomcat 7.0.21
Apache Tomcat 7.0.18
Apache Tomcat 7.0.14
Apache Tomcat 7.0.10
Apache Tomcat 7.0.12
Apache Tomcat 7.0.4
Apache Tomcat 7.0.8
Apache Tomcat 7.0.13
Apache Tomcat 7.0.5
Apache Tomcat 7.0.20
Apache Tomcat 7.0.17
Apache Tomcat 7.0.0
Apache Tomcat 7.0.3
Apache Tomcat 7.0.22
Apache Tomcat 7.0.9
Apache Tomcat 7.0.15
Apache Tomcat 7.0.23
Apache Tomcat 7.0.11
Apache Tomcat 7.0.2
Apache Tomcat 7.0.25
Apache Tomcat 7.0.16
Apache Tomcat 7.0.1
Apache Tomcat 7.0.7
Apache Tomcat 7.0.19
1.2
CVSSv2
CVE-2010-3718
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a...
Apache Tomcat 7.0.1
Apache Tomcat 7.0.2
Apache Tomcat 7.0.0
Apache Tomcat 7.0.3
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.7
Apache Tomcat 6.0.4
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.29
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0.24
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 6.0.28
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.5
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.27
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 5.5.30
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.3
Apache Tomcat 5.5.32
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 5.5.24
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.29
Apache Tomcat 5.5.19
Apache Tomcat 5.5.23
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-21012
CVE-2023-21075
CVE-2021-3923
CVE-2023-25664
CVE-2023-21034
dos
CVE-2022-46169
unprivileged
reflected XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »