Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*
  • CPE Name Search: true
There are 82 matching records.
Displaying matches 81 through 82.
Vuln ID Summary CVSS Severity
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

Published: November 26, 2010; 3:00:04 PM -0500
V3.x:(not available)
V2.0: 4.3 MEDIUM
CVE-2010-2227

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."

Published: July 13, 2010; 1:30:03 PM -0400
V3.x:(not available)
V2.0: 6.4 MEDIUM