Show filters
52 Total Results
Displaying 51-52 of 52
Sort by:
Attacker Value
Unknown
CVE-2011-1419
Disclosure Date: March 14, 2011 (last updated October 04, 2023)
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
0
Attacker Value
Unknown
CVE-2011-0534
Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
0