Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache tomcat 6.0 vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2016-1240
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before...
Apache Tomcat 6.0
Apache Tomcat 7.0
Apache Tomcat 8.0
1 EDB exploit available
5 Github repositories available
NA
CVE-2010-4312
The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie....
Apache Tomcat 6.0.15
Apache Tomcat 6.0
Apache Tomcat 6.0.28
Apache Tomcat 6.0.17
Apache Tomcat 6.0.18
Apache Tomcat 6.0.2
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.14
Apache Tomcat 6.0.6
Apache Tomcat 6.0.1
Apache Tomcat 6.0.0
Apache Tomcat 6.0.13
Apache Tomcat 6.0.24
Apache Tomcat 6.0.9
Apache Tomcat 6.0.29
Apache Tomcat 6.0.4
Apache Tomcat 6.0.3
Apache Tomcat 6.0.10
Apache Tomcat 6.0.20
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 6.0.5
Apache Tomcat 6.0.27
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
NA
CVE-2009-2901
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests....
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 6.0.7
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 6.0.4
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 6.0.15
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 5.5.3
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 5.5.24
Apache Tomcat 6.0.18
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 6.0.5
Apache Tomcat 5.5.17
Apache Tomcat 5.5.19
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 5.5.23
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
NA
CVE-2009-2902
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename....
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 6.0.7
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 6.0.4
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 6.0.15
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 5.5.3
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 5.5.24
Apache Tomcat 6.0.18
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 6.0.5
Apache Tomcat 5.5.17
Apache Tomcat 5.5.19
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 5.5.23
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
NA
CVE-2012-4431
org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier....
Apache Tomcat 6.0.15
Apache Tomcat 6.0.8
Apache Tomcat 6.0.9
Apache Tomcat 6.0.4
Apache Tomcat 6.0.28
Apache Tomcat 6.0.1
Apache Tomcat 6.0.0
Apache Tomcat 6.0.32
Apache Tomcat 6.0.13
Apache Tomcat 6.0.24
Apache Tomcat 6.0.16
Apache Tomcat 6.0.14
Apache Tomcat 6.0.6
Apache Tomcat 6.0.29
Apache Tomcat 6.0.7
Apache Tomcat 6.0.17
Apache Tomcat 6.0.27
Apache Tomcat 6.0.3
Apache Tomcat 6.0.11
Apache Tomcat 6.0.10
Apache Tomcat 6.0.30
Apache Tomcat 6.0
Apache Tomcat 6.0.35
Apache Tomcat 6.0.2
Apache Tomcat 6.0.5
Apache Tomcat 6.0.31
Apache Tomcat 6.0.12
Apache Tomcat 6.0.33
Apache Tomcat 6.0.18
Apache Tomcat 6.0.26
Apache Tomcat 6.0.20
Apache Tomcat 6.0.19
Apache Tomcat 7.0.23
Apache Tomcat 7.0.2
Apache Tomcat 7.0.6
Apache Tomcat 7.0.21
Apache Tomcat 7.0.17
Apache Tomcat 7.0.14
Apache Tomcat 7.0.28
Apache Tomcat 7.0.12
Apache Tomcat 7.0.9
Apache Tomcat 7.0.8
Apache Tomcat 7.0.13
Apache Tomcat 7.0.5
Apache Tomcat 7.0.1
Apache Tomcat 7.0.20
Apache Tomcat 7.0.0
Apache Tomcat 7.0.3
Apache Tomcat 7.0.19
Apache Tomcat 7.0.22
Apache Tomcat 7.0.4
Apache Tomcat 7.0.16
Apache Tomcat 7.0.7
Apache Tomcat 7.0.18
Apache Tomcat 7.0.15
Apache Tomcat 7.0.10
Apache Tomcat 7.0.11
Apache Tomcat 7.0.25
Apache Tomcat 7.0.30
NA
CVE-2012-3544
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data....
Apache Tomcat 6.0.33
Apache Tomcat 6.0.0
Apache Tomcat 6.0.6
Apache Tomcat 6.0.4
Apache Tomcat 6.0.11
Apache Tomcat 6.0.7
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.9
Apache Tomcat 6.0.10
Apache Tomcat 6.0.31
Apache Tomcat 6.0.29
Apache Tomcat 6.0.3
Apache Tomcat 6.0.1
Apache Tomcat 6.0.24
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 6.0.32
Apache Tomcat 6.0.28
Apache Tomcat 6.0.14
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.2
Apache Tomcat 6.0.5
Apache Tomcat 6.0.30
Apache Tomcat 6.0.13
Apache Tomcat 6.0.8
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.27
Apache Tomcat 6.0.35
Apache Tomcat 6.0.16
Apache Tomcat 6.0.36
Apache Tomcat 7.0.2
Apache Tomcat 7.0.12
Apache Tomcat 7.0.20
Apache Tomcat 7.0.8
Apache Tomcat 7.0.1
Apache Tomcat 7.0.5
Apache Tomcat 7.0.4
Apache Tomcat 7.0.22
Apache Tomcat 7.0.28
Apache Tomcat 7.0.0
Apache Tomcat 7.0.6
Apache Tomcat 7.0.18
Apache Tomcat 7.0.14
Apache Tomcat 7.0.11
Apache Tomcat 7.0.23
Apache Tomcat 7.0.7
Apache Tomcat 7.0.13
Apache Tomcat 7.0.15
Apache Tomcat 7.0.19
Apache Tomcat 7.0.16
Apache Tomcat 7.0.10
Apache Tomcat 7.0.25
Apache Tomcat 7.0.21
Apache Tomcat 7.0.17
Apache Tomcat 7.0.9
Apache Tomcat 7.0.3
NA
CVE-2011-1184
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access...
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 5.5.30
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.3
Apache Tomcat 5.5.32
Apache Tomcat 5.5.31
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 5.5.33
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 5.5.24
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.29
Apache Tomcat 5.5.19
Apache Tomcat 5.5.23
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.7
Apache Tomcat 6.0.4
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.31
Apache Tomcat 6.0.29
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0.24
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 6.0.32
Apache Tomcat 6.0.28
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.5
Apache Tomcat 6.0.30
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.27
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
Apache Tomcat 7.0.8
Apache Tomcat 7.0.1
Apache Tomcat 7.0.2
Apache Tomcat 7.0.5
Apache Tomcat 7.0.0
Apache Tomcat 7.0.6
Apache Tomcat 7.0.11
Apache Tomcat 7.0.7
Apache Tomcat 7.0.10
Apache Tomcat 7.0.9
Apache Tomcat 7.0.4
Apache Tomcat 7.0.3
NA
CVE-2008-5515
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access...
Apache Tomcat 5.5.27
Apache Tomcat 4.1.2
Apache Tomcat 4.1.35
Apache Tomcat 4.1.36
Apache Tomcat 5.5.18
Apache Tomcat 4.1.21
Apache Tomcat 6.0.6
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 4.1.24
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 6.0.7
Apache Tomcat 5.5.11
Apache Tomcat 4.1.25
Apache Tomcat 6.0.4
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 4.1.39
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 4.1.27
Apache Tomcat 6.0.15
Apache Tomcat 4.1.30
Apache Tomcat 4.1.38
Apache Tomcat 4.1.11
Apache Tomcat 5.5.21
Apache Tomcat 4.1.18
Apache Tomcat 5.5.22
Apache Tomcat 4.1.14
Apache Tomcat 6.0.10
Apache Tomcat 6.0.3
Apache Tomcat 4.1.19
Apache Tomcat 6.0.9
Apache Tomcat 4.1.31
Apache Tomcat 5.5.3
Apache Tomcat 4.1.16
Apache Tomcat 4.1.29
Apache Tomcat 6.0.17
Apache Tomcat 4.1.22
Apache Tomcat 6.0
Apache Tomcat 4.1.26
Apache Tomcat 4.1.13
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 6.0.0
Apache Tomcat 4.1.17
Apache Tomcat 6.0.14
Apache Tomcat 5.5.2
Apache Tomcat 4.1.33
Apache Tomcat 5.5.0
Apache Tomcat 4.1.1
Apache Tomcat 5.5.13
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 5.5.24
Apache Tomcat 4.1.12
Apache Tomcat 4.1.28
Apache Tomcat 6.0.18
Apache Tomcat 4.1.15
Apache Tomcat 4.1.10
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 4.1.0
Apache Tomcat 6.0.5
Apache Tomcat 4.1.20
Apache Tomcat 5.5.17
Apache Tomcat 4.1.3
Apache Tomcat 5.5.19
Apache Tomcat 4.1.23
Apache Tomcat 4.1.34
Apache Tomcat 4.1.32
Apache Tomcat 4.1.37
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 5.5.23
Apache Tomcat 6.0.16
NA
CVE-2014-0075
Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remote attackers to cause a denial of service (resource consumption) via a malformed...
Apache Tomcat 7.0.2
Apache Tomcat 7.0.49
Apache Tomcat 7.0.12
Apache Tomcat 7.0.20
Apache Tomcat 7.0.34
Apache Tomcat 7.0.8
Apache Tomcat 7.0.1
Apache Tomcat 7.0.5
Apache Tomcat 7.0.4
Apache Tomcat 7.0.22
Apache Tomcat 7.0.39
Apache Tomcat 7.0.26
Apache Tomcat 7.0.46
Apache Tomcat 7.0.28
Apache Tomcat 7.0.0
Apache Tomcat 7.0.50
Apache Tomcat 7.0.6
Apache Tomcat 7.0.18
Apache Tomcat 7.0.14
Apache Tomcat 7.0.48
Apache Tomcat 7.0.11
Apache Tomcat 7.0.23
Apache Tomcat 7.0.44
Apache Tomcat 7.0.7
Apache Tomcat 7.0.52
Apache Tomcat 7.0.42
Apache Tomcat 7.0.37
Apache Tomcat 7.0.29
Apache Tomcat 7.0.45
Apache Tomcat 7.0.13
Apache Tomcat 7.0.47
Apache Tomcat 7.0.41
Apache Tomcat 7.0.31
Apache Tomcat 7.0.30
Apache Tomcat 7.0.15
Apache Tomcat 7.0.19
Apache Tomcat 7.0.16
Apache Tomcat 7.0.10
Apache Tomcat 7.0.36
Apache Tomcat 7.0.25
Apache Tomcat 7.0.35
Apache Tomcat 7.0.43
Apache Tomcat 7.0.32
Apache Tomcat 7.0.38
Apache Tomcat 7.0.21
Apache Tomcat 7.0.27
Apache Tomcat 7.0.24
Apache Tomcat 7.0.17
Apache Tomcat 7.0.40
Apache Tomcat 7.0.9
Apache Tomcat 7.0.3
Apache Tomcat 7.0.33
Apache Tomcat 8.0.1
Apache Tomcat 8.0.0
Apache Tomcat 8.0.3
Apache Tomcat 6.0.33
Apache Tomcat 6.0.0
Apache Tomcat 6.0.6
Apache Tomcat 6.0.4
Apache Tomcat 6.0.11
Apache Tomcat
Apache Tomcat 6
Apache Tomcat 6.0.7
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.9
Apache Tomcat 6.0.10
Apache Tomcat 6.0.31
Apache Tomcat 6.0.29
Apache Tomcat 6.0.3
Apache Tomcat 6.0.1
Apache Tomcat 6.0.24
Apache Tomcat 6.0.37
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 6.0.32
Apache Tomcat 6.0.28
Apache Tomcat 6.0.14
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.2
Apache Tomcat 6.0.5
Apache Tomcat 6.0.30
Apache Tomcat 6.0.13
Apache Tomcat 6.0.8
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.27
Apache Tomcat 6.0.35
Apache Tomcat 6.0.16
Apache Tomcat 6.0.36
2 Articles available
NA
CVE-2011-5063
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a...
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 5.5.30
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.3
Apache Tomcat 5.5.32
Apache Tomcat 5.5.31
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 5.5.33
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 5.5.24
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.29
Apache Tomcat 5.5.19
Apache Tomcat 5.5.23
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.7
Apache Tomcat 6.0.4
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.31
Apache Tomcat 6.0.29
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0.24
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 6.0.32
Apache Tomcat 6.0.28
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.5
Apache Tomcat 6.0.30
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.27
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
Apache Tomcat 7.0.8
Apache Tomcat 7.0.1
Apache Tomcat 7.0.2
Apache Tomcat 7.0.5
Apache Tomcat 7.0.0
Apache Tomcat 7.0.6
Apache Tomcat 7.0.11
Apache Tomcat 7.0.7
Apache Tomcat 7.0.10
Apache Tomcat 7.0.9
Apache Tomcat 7.0.4
Apache Tomcat 7.0.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49380
CVE-2023-49447
CVE-2023-22522
CVE-2023-45285
CVE-2023-22523
open redirect
CVE-2023-49105
remote attackers
inject
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »