5
CVSSv2

CVE-2011-0534

Published: 10/02/2011 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Apache Tomcat 7.0.0 up to and including 7.0.6 and 6.0.0 up to and including 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote malicious users to cause a denial of service (OutOfMemoryError) via a crafted request.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat 7.0.0

apache tomcat 7.0.1

apache tomcat 7.0.2

apache tomcat 7.0.3

apache tomcat 7.0.6

apache tomcat 7.0.4

apache tomcat 7.0.5

apache tomcat 6.0.15

apache tomcat 6.0.14

apache tomcat 6.0.17

apache tomcat 6.0.18

apache tomcat 6.0.26

apache tomcat 6.0.13

apache tomcat 6.0.16

apache tomcat 6.0.30

apache tomcat 6.0.6

apache tomcat 6.0.7

apache tomcat 6.0.1

apache tomcat 6.0.0

apache tomcat 6.0.5

apache tomcat 6.0.24

apache tomcat 6.0.12

apache tomcat 6.0.29

apache tomcat 6.0.28

apache tomcat 6.0.3

apache tomcat 6.0.2

apache tomcat 6.0.20

apache tomcat 6.0.19

apache tomcat 6.0.8

apache tomcat 6.0.9

apache tomcat 6.0.27

apache tomcat 6.0.4

apache tomcat 6.0.11

apache tomcat 6.0.10

Vendor Advisories

Debian Bug report logs - #612257 Three Tomcat vulnerabilities Package: tomcat6; Maintainer for tomcat6 is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 7 Feb 2011 08:45:14 UTC Severity: grave Tags: security Fixed in ver ...
An attacker could send crafted input to Tomcat and cause it to crash or read and write arbitrary files ...
Several vulnerabilities were discovered in the Tomcat Servlet and JSP engine: CVE-2010-3718 It was discovered that the SecurityManager insufficiently restricted the working directory CVE-2011-0013 It was discovered that the HTML manager interface is affected by cross-site scripting CVE-2011-0534 It was discovered that N ...