Vulnerabilities
Vulnerable Software
Apache:  >> Tomcat  >> 7.0.47  Security Vulnerabilities
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
CVSS Score
7.5
EPSS Score
0.828
Published
2014-04-01
Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."
CVSS Score
2.1
EPSS Score
0.007
Published
2014-02-15
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
CVSS Score
5.0
EPSS Score
0.096
Published
2012-11-30


Contact Us

Shodan ® - All rights reserved