Apache / Apache Tomcat
138 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-23672 | Apache Tomcat: WebSocket DoS with incomplete closing handshake | HIGH | 7.5 | Mar 13, 2024 |
| CVE-2024-24549 | Apache Tomcat: HTTP/2 header handling DoS | MEDIUM | 6.6 | Mar 13, 2024 |
| CVE-2024-21733 | Apache Tomcat: Leaking of unrelated request bodies in default error page | MEDIUM | 5.3 | Jan 19, 2024 |
| CVE-2023-46589 | Apache Tomcat: HTTP request smuggling via malformed trailer headers | HIGH | 7.5 | Nov 28, 2023 |
| CVE-2023-45648 | Apache Tomcat: Trailer header parsing too lenient | MEDIUM | 5.3 | Oct 10, 2023 |
| CVE-2023-42795 | Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests | MEDIUM | 5.3 | Oct 10, 2023 |
| CVE-2023-42794 | Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on Windows | MEDIUM | 5.9 | Oct 10, 2023 |
| CVE-2023-41080 | Apache Tomcat: Open redirect with FORM authentication | MEDIUM | 6.1 | Aug 25, 2023 |
| CVE-2023-34981 | Apache Tomcat: AJP response header mix-up | HIGH | 7.5 | Jun 21, 2023 |
| CVE-2023-28709 | Apache Tomcat: Fix for CVE-2023-24998 is incomplete | HIGH | 7.5 | May 22, 2023 |
| CVE-2023-28708 | Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurations | MEDIUM | 4.3 | Mar 22, 2023 |
| CVE-2023-24998 | Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts | HIGH | 7.5 | Feb 20, 2023 |
| CVE-2022-45143 | Apache Tomcat: JsonErrorReportValve escaping | HIGH | 7.5 | Jan 3, 2023 |
| CVE-2022-42252 | Apache Tomcat request smuggling via malformed content-length | HIGH | 7.5 | Nov 1, 2022 |
| CVE-2021-43980 | Apache Tomcat: Information disclosure | LOW | 3.7 | Sep 28, 2022 |
| CVE-2022-34305 | XSS in examples web application | MEDIUM | 6.1 | Jun 23, 2022 |
| CVE-2022-25762 | Response mix-up with WebSocket concurrent send and close | HIGH | 8.6 | May 13, 2022 |
| CVE-2022-29885 | EncryptInterceptor does not provide complete protection on insecure networks | HIGH | 7.5 | May 12, 2022 |
| CVE-2022-23181 | Local privilege escalation with FileStore | HIGH | 7.0 | Jan 27, 2022 |
| CVE-2021-42340 | DoS via memory leak with WebSocket connections | HIGH | 7.5 | Oct 14, 2021 |
| CVE-2021-41079 | Apache Tomcat DoS with unexpected TLS packet | HIGH | 7.5 | Sep 16, 2021 |
| CVE-2021-33037 | Incorrect Transfer-Encoding handling with HTTP/1.0 | MEDIUM | 5.3 | Jul 12, 2021 |
| CVE-2021-30640 | Auth weakness in JNDIRealm | MEDIUM | 6.5 | Jul 12, 2021 |
| CVE-2021-30639 | DoS after non-blocking IO error | HIGH | 7.5 | Jul 12, 2021 |
| CVE-2021-25329 | Incomplete fix for CVE-2020-9484 | HIGH | 7.0 | Mar 1, 2021 |
Showing 76 to 100 of 138 CVEs