Show filters
63 Total Results
Displaying 61-63 of 63
Sort by:
Attacker Value
Unknown
CVE-2005-1754
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.
0
Attacker Value
Unknown
CVE-2005-3510
Disclosure Date: November 06, 2005 (last updated February 22, 2025)
Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
0
Attacker Value
Unknown
CVE-2005-2090
Disclosure Date: July 05, 2005 (last updated February 22, 2025)
Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
0