Show filters
33 Total Results
Displaying 31-33 of 33
Sort by:
Attacker Value
Unknown
CVE-2012-0022
Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
0
Attacker Value
Unknown
CVE-2011-4858
Disclosure Date: January 05, 2012 (last updated October 04, 2023)
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
0
Attacker Value
Unknown
CVE-2011-3376
Disclosure Date: November 11, 2011 (last updated October 04, 2023)
org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
0