Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2003-0045

Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.
0
Attacker Value
Unknown

CVE-2003-0042

Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
0
Attacker Value
Unknown

CVE-2003-0043

Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
0
Attacker Value
Unknown

CVE-2002-2006

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
0
Attacker Value
Unknown

CVE-2002-1148

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
0
Attacker Value
Unknown

CVE-2000-0760

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
0
Attacker Value
Unknown

CVE-2000-0759

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
0
Attacker Value
Unknown

CVE-2000-0672

Disclosure Date: July 20, 2000 (last updated October 03, 2023)
The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.
0