CRITICAL9.8CVE-2025-24813⚠ KEVApache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT from 0, < 10.1.34-0+deb12u2
CRITICAL9.8CVE-2025-24813⚠ KEVApache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT from 0, < 10.1.34-0+deb12u2
CRITICAL9.8Apache Tomcat: HTTP/2 request headers not validated
from 0, < 10.1.55-1~deb12u1
CRITICAL9.8Apache Tomcat: Digest authenticator will authenticate any unknown user
from 0, < 10.1.55-1~deb12u1
CRITICAL9.8Apache Tomcat: Bypass of rules in Rewrite Valve
from 0, < 10.1.40-1
CRITICAL9.8Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete
from 0, < 10.1.34-0+deb12u1
CRITICAL9.8Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
from 0, < 10.1.34-0+deb12u1
CRITICAL9.8Apache Tomcat: Authentication bypass when using Jakarta Authentication API
from 0, < 10.1.34-0+deb12u1
CRITICAL9.6Apache Tomcat: console manipulation via escape sequences in log messages
from 0, < 10.1.52-1~deb12u1
CRITICAL9.1Apache Tomcat: EncryptInterceptor requirements not clearly documented
from 0
CRITICAL9.1Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
from 0
CRITICAL9.1Apache Tomcat: Security constraints not correctly applied
from 0, < 10.1.55-1~deb12u1
CRITICAL9.1Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
from 0, < 10.1.55-1~deb12u1
CRITICAL9.1Apache Tomcat: Client certificate verification bypass due to virtual host mapping
from 0, < 10.1.52-1~deb12u1
HIGH7.5Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
from 0, < 10.1.55-1~deb12u1
HIGH7.5Apache Tomcat: LockOutRealm treats user names as case-sensitive
from 0, < 10.1.55-1~deb12u1
HIGH7.5Apache Tomcat: Incomplete escaping of JSON access logs
from 0, < 10.1.55-1~deb12u1
HIGH7.5Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
from 0, < 10.1.55-1~deb12u1
HIGH7.5Apache Tomcat: Request smuggling via invalid chunk extension
from 0, < 10.1.55-1~deb12u1
HIGH7.5Apache Tomcat: TLS cipher order is not preserved
from 0, < 10.1.55-1~deb12u1
HIGH7.5Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
from 0, < 10.1.52-1~deb12u1
HIGH7.5Apache Tomcat: h2 DoS - Made You Reset
from 0, < 10.1.52-1~deb12u1
HIGH7.5Apache Tomcat: DoS via excessive h2 streams at connection start
from 0, < 10.1.52-1~deb12u1
HIGH7.5Apache Tomcat: DoS via integer overflow in multipart file upload
from 0, < 10.1.52-1~deb12u1
HIGH7.5Apache Tomcat: FileUpload large number of parts with headers DoS
from 0, < 10.1.52-1~deb12u1
HIGH7.5Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
from 0, < 10.1.52-1~deb12u1
HIGH7.5Apache Tomcat: Security constraint bypass for pre/post-resources
from 0, < 10.1.52-1~deb12u1
HIGH7.5Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
from 0, < 10.1.40-1
HIGH7.5Apache Tomcat: HTTP/2 excess header handling DoS
from 0, < 10.1.34-0+deb12u1
HIGH7.5Apache Tomcat: HTTP/2 excess header handling DoS
from 0, < 10.1.34-0+deb12u1
HIGH7.5Apache Tomcat: HTTP/2 header handling DoS
from 0, < 10.1.6-1+deb12u2
HIGH7.5Apache Tomcat: HTTP request smuggling via malformed trailer headers
from 0, < 10.1.6-1+deb12u2
HIGH7.5Apache Tomcat: HTTP request smuggling via malformed trailer headers
from 0, < 10.1.6-1+deb12u2
HIGH7.5Apache Tomcat: Fix for CVE-2023-24998 is incomplete
from 0, < 10.1.6-1+deb12u1
HIGH7.5Apache Tomcat: Fix for CVE-2023-24998 is incomplete
from 0, < 10.1.6-1+deb12u1
HIGH7.5Apache Tomcat: AJP response header mix-up
from 0, < 10.1.10-1
HIGH7.5tomcat9 - security update
from 0, < 10.1.5-1
HIGH7.3Apache Tomcat: WebSocket authentication header exposure
from 0, < 10.1.55-1~deb12u1
HIGH7.3Apache Tomcat: Security constraint bypass for CGI scripts
from 0, < 10.1.52-1~deb12u1
HIGH7.3Apache Tomcat: Security constraint bypass for CGI scripts
from 0, < 10.1.52-1~deb12u1
MEDIUM6.5Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
from 0, < 10.1.55-1~deb12u1
MEDIUM6.5Apache Tomcat: Request/response mix-up with HTTP/2
from 0, < 10.1.31-1
MEDIUM6.3Apache Tomcat: WebSocket DoS with incomplete closing handshake
from 0, < 10.1.6-1+deb12u2
MEDIUM6.1Apache Tomcat: Occasionally open redirect
from 0, < 10.1.55-1~deb12u1
MEDIUM6.1Apache Tomcat: Incorrect JSP tag recycling leads to XSS
from 0, < 10.1.33-1
MEDIUM6.1Apache Tomcat: Open redirect with FORM authentication
from 0, < 10.1.6-1+deb12u1
MEDIUM5.3Apache Tomcat: Fix for CVE-2025-66614 is incomplete
from 0, < 10.1.55-1~deb12u1
MEDIUM5.3Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS
from 0, < 10.1.52-1~deb12u1
MEDIUM5.3Apache Tomcat: Trailer header parsing too lenient
from 0, < 10.1.6-1+deb12u1
MEDIUM5.3Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests
from 0, < 10.1.6-1+deb12u1
MEDIUM4.3Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurations
from 0, < 10.1.6-1
LOW3.7Apache Tomcat: AJP secret compared in non-constant time
from 0, < 10.1.55-1~deb12u1
LOW3.7Apache Tomcat: Security constraint bypass with HTTP/0.9
from 0, < 10.1.52-1~deb12u1