Show filters
54 Total Results
Displaying 51-54 of 54
Sort by:
Attacker Value
Unknown
CVE-2011-1088
Disclosure Date: March 14, 2011 (last updated October 04, 2023)
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
0
Attacker Value
Unknown
CVE-2011-1419
Disclosure Date: March 14, 2011 (last updated October 04, 2023)
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
0
Attacker Value
Unknown
CVE-2011-0013
Disclosure Date: February 19, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
0
Attacker Value
Unknown
CVE-2011-0534
Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
0