Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache tomcat 5.5.19 vulnerabilities and exploits
(subscribe to this query)
231
VMScore
CVE-2008-4308
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request....
Apache Tomcat 5.5.18
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.11
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 4.1.33
Apache Tomcat 5.5.13
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.19
Apache Tomcat 4.1.34
Apache Tomcat 4.1.32
383
VMScore
CVE-2007-6286
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as...
Apache Tomcat 5.5.15
Apache Tomcat 5.5.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.20
Apache Tomcat 5.5.21
Apache Tomcat 6.0.10
Apache Tomcat 6.0.11
Apache Tomcat 6.0.4
Apache Tomcat 6.0.5
Apache Tomcat 5.5.17
Apache Tomcat 5.5.18
Apache Tomcat 5.5.19
Apache Tomcat 6.0.0
Apache Tomcat 6.0.1
Apache Tomcat 6.0.2
Apache Tomcat 6.0.3
Apache Tomcat 5.5.13
Apache Tomcat 5.5.14
Apache Tomcat 5.5.22
Apache Tomcat 5.5.23
Apache Tomcat 6.0.12
Apache Tomcat 6.0.13
Apache Tomcat 6.0.6
Apache Tomcat 6.0.7
Apache Tomcat 5.5.16
Apache Tomcat 5.5.24
Apache Tomcat 5.5.25
Apache Tomcat 6.0.14
Apache Tomcat 6.0.15
Apache Tomcat 6.0.8
Apache Tomcat 6.0.9
570
VMScore
CVE-2007-5342
The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as...
Apache Tomcat 5.5.18
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 6.0.7
Apache Tomcat 5.5.11
Apache Tomcat 6.0.4
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 6.0.15
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 6.0.10
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 6.0.14
Apache Tomcat 5.5.13
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 5.5.24
Apache Tomcat 5.5.16
Apache Tomcat 6.0.5
Apache Tomcat 5.5.17
Apache Tomcat 5.5.19
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 5.5.23
Apache Tomcat 6.0.8
383
VMScore
CVE-2008-1947
Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add....
Apache Tomcat 5.5.18
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 6.0.7
Apache Tomcat 5.5.11
Apache Tomcat 6.0.4
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 6.0.15
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 6.0.10
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 5.5.13
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 5.5.24
Apache Tomcat 5.5.16
Apache Tomcat 6.0.5
Apache Tomcat 5.5.17
Apache Tomcat 5.5.19
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 5.5.23
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
435
VMScore
CVE-2007-3386
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action....
Apache Tomcat 5.5.13
Apache Tomcat 5.5.14
Apache Tomcat 5.5.20
Apache Tomcat 5.5.21
Apache Tomcat 5.5.6
Apache Tomcat 5.5.7
Apache Tomcat 5.5.8
Apache Tomcat 6.0.13
Apache Tomcat 6.0.2
Apache Tomcat 6.0.9
Apache Tomcat 5.5.0
Apache Tomcat 5.5.15
Apache Tomcat 5.5.16
Apache Tomcat 5.5.22
Apache Tomcat 5.5.23
Apache Tomcat 5.5.9
Apache Tomcat 6.0.0
Apache Tomcat 6.0.3
Apache Tomcat 6.0.4
Apache Tomcat 5.5.1
Apache Tomcat 5.5.10
Apache Tomcat 5.5.17
Apache Tomcat 5.5.18
Apache Tomcat 5.5.24
Apache Tomcat 5.5.3
Apache Tomcat 6.0.1
Apache Tomcat 6.0.10
Apache Tomcat 6.0.5
Apache Tomcat 6.0.6
Apache Tomcat 5.5.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.19
Apache Tomcat 5.5.2
Apache Tomcat 5.5.4
Apache Tomcat 5.5.5
Apache Tomcat 6.0.11
Apache Tomcat 6.0.12
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
1 EDB exploit available
720
VMScore
CVE-2010-2227
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that...
Apache Tomcat 5.5.27
Apache Tomcat 5.5.9
Apache Tomcat 5.5.17
Apache Tomcat 5.5.18
Apache Tomcat 5.5.3
Apache Tomcat 5.5.22
Apache Tomcat 5.5.0
Apache Tomcat 5.5.8
Apache Tomcat 5.5.7
Apache Tomcat 5.5.15
Apache Tomcat 5.5.16
Apache Tomcat 5.5.13
Apache Tomcat 5.5.23
Apache Tomcat 5.5.26
Apache Tomcat 5.5.25
Apache Tomcat 5.5.10
Apache Tomcat 5.5.6
Apache Tomcat 5.5.5
Apache Tomcat 5.5.14
Apache Tomcat 5.5.11
Apache Tomcat 5.5.20
Apache Tomcat 5.5.21
Apache Tomcat 5.5.1
Apache Tomcat 5.5.28
Apache Tomcat 5.5.4
Apache Tomcat 5.5.29
Apache Tomcat 5.5.12
Apache Tomcat 5.5.24
Apache Tomcat 5.5.19
Apache Tomcat 5.5.2
Apache Tomcat 6.0.15
Apache Tomcat 6.0.18
Apache Tomcat 6.0.1
Apache Tomcat 6.0.0
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.14
Apache Tomcat 6.0.6
Apache Tomcat 6.0.5
Apache Tomcat 6.0.4
Apache Tomcat 6.0.10
Apache Tomcat 6.0.20
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 6.0.3
Apache Tomcat 6.0.2
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.9
Apache Tomcat 6.0.17
Apache Tomcat 6.0.13
Apache Tomcat 6.0.24
Apache Tomcat 6.0.26
Apache Tomcat 6.0.27
Apache Tomcat 7.0.0
2 Metasploit modules available
1 Github repository available
383
VMScore
CVE-2011-0013
Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag....
Apache Tomcat 7.0.1
Apache Tomcat 7.0.2
Apache Tomcat 7.0.5
Apache Tomcat 7.0.0
Apache Tomcat 7.0.4
Apache Tomcat 7.0.3
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.7
Apache Tomcat 6.0.4
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.29
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0.24
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 6.0.28
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.5
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.27
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 5.5.30
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.3
Apache Tomcat 5.5.31
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 5.5.24
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.29
Apache Tomcat 5.5.19
Apache Tomcat 5.5.23
107
VMScore
CVE-2010-3718
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a...
Apache Tomcat 7.0.1
Apache Tomcat 7.0.2
Apache Tomcat 7.0.0
Apache Tomcat 7.0.3
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.7
Apache Tomcat 6.0.4
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.29
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0.24
Apache Tomcat 6.0.17
Apache Tomcat 6.0
Apache Tomcat 6.0.28
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.5
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.27
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 5.5.30
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.3
Apache Tomcat 5.5.32
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 5.5.24
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.29
Apache Tomcat 5.5.19
Apache Tomcat 5.5.23
265
VMScore
CVE-2010-1157
Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the...
Apache Tomcat 5.5.27
Apache Tomcat 5.5.18
Apache Tomcat 5.5.12
Apache Tomcat 5.5.14
Apache Tomcat 5.5.10
Apache Tomcat 5.5.4
Apache Tomcat 5.5.7
Apache Tomcat 5.5.1
Apache Tomcat 5.5.11
Apache Tomcat 5.5.28
Apache Tomcat 5.5.6
Apache Tomcat 5.5.26
Apache Tomcat 5.5.20
Apache Tomcat 5.5.15
Apache Tomcat 5.5.5
Apache Tomcat 5.5.21
Apache Tomcat 5.5.22
Apache Tomcat 5.5.3
Apache Tomcat 5.5.9
Apache Tomcat 5.5.25
Apache Tomcat 5.5.2
Apache Tomcat 5.5.0
Apache Tomcat 5.5.13
Apache Tomcat 5.5.24
Apache Tomcat 5.5.8
Apache Tomcat 5.5.16
Apache Tomcat 5.5.17
Apache Tomcat 5.5.29
Apache Tomcat 5.5.19
Apache Tomcat 5.5.23
Apache Tomcat 6.0.6
Apache Tomcat 6.0.11
Apache Tomcat 6.0.7
Apache Tomcat 6.0.4
Apache Tomcat 6.0.15
Apache Tomcat 6.0.20
Apache Tomcat 6.0.10
Apache Tomcat 6.0.3
Apache Tomcat 6.0.9
Apache Tomcat 6.0.24
Apache Tomcat 6.0.17
Apache Tomcat 6.0.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 6.0.18
Apache Tomcat 6.0.5
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 6.0.26
Apache Tomcat 6.0.19
Apache Tomcat 6.0.16
Apache Tomcat 6.0.8
1 EDB exploit available
516
VMScore
CVE-2009-2693
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry....
Apache Tomcat 5.5.0
Apache Tomcat 5.5.8
Apache Tomcat 5.5.7
Apache Tomcat 5.5.6
Apache Tomcat 5.5.13
Apache Tomcat 5.5.14
Apache Tomcat 5.5.23
Apache Tomcat 5.5.20
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 6.0.4
Apache Tomcat 6.0.3
Apache Tomcat 6.0.19
Apache Tomcat 6.0.20
Apache Tomcat 5.5.1
Apache Tomcat 5.5.28
Apache Tomcat 5.5.17
Apache Tomcat 5.5.18
Apache Tomcat 5.5.24
Apache Tomcat 5.5.3
Apache Tomcat 5.5.2
Apache Tomcat 6.0.15
Apache Tomcat 6.0.18
Apache Tomcat 6.0.1
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 5.5.25
Apache Tomcat 5.5.10
Apache Tomcat 5.5.5
Apache Tomcat 5.5.4
Apache Tomcat 5.5.11
Apache Tomcat 5.5.12
Apache Tomcat 5.5.21
Apache Tomcat 5.5.19
Apache Tomcat 6.0.9
Apache Tomcat 6.0.17
Apache Tomcat 6.0.2
Apache Tomcat 6.0.13
Apache Tomcat 5.5.27
Apache Tomcat 5.5.9
Apache Tomcat 5.5.15
Apache Tomcat 5.5.16
Apache Tomcat 5.5.22
Apache Tomcat 5.5.26
Apache Tomcat 6.0
Apache Tomcat 6.0.14
Apache Tomcat 6.0.6
Apache Tomcat 6.0.0
Apache Tomcat 6.0.5
Apache Tomcat 6.0.10
Apache Tomcat 6.0.16
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30758
CSRF
CVE-2021-44228
CVE-2023-33633
XPath injection
CVE-2023-33735
CVE-2023-29336
CVE-2023-34312
cache poisoning
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »