This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:apache:tomcat:4.1.3
Detail
VendorApacheFirst view 2002-12-31
ProductTomcatLast view 2012-11-30
Version4.1.3TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:apache:tomcat

Activity : Yearly

Related : CVE

 DateAlertAccess VectorAccess ComplexityAuthentification
52012-11-30CVE-2012-5568NetworkLowNone Requ...
7.52009-11-12CVE-2009-3548NetworkLowNone Requ...
52009-06-16CVE-2008-5515NetworkLowNone Requ...
4.62009-06-05CVE-2009-0783LocalLowNone Requ...
4.32009-06-05CVE-2009-0580NetworkMediumNone Requ...
Hide | Show 12 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
52009-06-05CVE-2009-0033NetworkLowNone Requ...
2.62009-04-09CVE-2008-5519NetworkHighNone Requ...
4.32009-03-09CVE-2009-0781NetworkMediumNone Requ...
4.32008-10-13CVE-2008-3271NetworkMediumNone Requ...
52008-08-03CVE-2008-2370NetworkLowNone Requ...
4.32008-08-03CVE-2008-1232NetworkMediumNone Requ...
4.32007-08-14CVE-2007-3385NetworkMediumNone Requ...
4.32007-08-14CVE-2007-3382NetworkMediumNone Requ...
4.32007-07-25CVE-2007-3383NetworkMediumNone Requ...
3.52007-06-14CVE-2007-2450NetworkMediumRequires ...
2.62005-10-06CVE-2005-3164NetworkHighNone Requ...
7.82002-12-31CVE-2002-2272NetworkLowNone Requ...

CWE : Common Weakness Enumeration

%idName
37% (6)CWE-200Information Exposure
18% (3)CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
12% (2)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path ...
6% (1)CWE-264Permissions, Privileges, and Access Controls
6% (1)CWE-255Credentials Management
Hide | Show 3 More...
%idName
6% (1)CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer
6% (1)CWE-20Improper Input Validation
6% (1)CWE-16Configuration

Oval Markup Language : Definitions

OvalIDName
oval:org.mitre.oval:def:11287Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2...
oval:org.mitre.oval:def:11269Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1...
oval:org.mitre.oval:def:9549Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1...
oval:org.mitre.oval:def:5985Security vulnerability in the HttpServletResponse.sendError method in Tomcat ...
oval:org.mitre.oval:def:11181Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.3...
Hide | Show 13 More...
idName
oval:org.mitre.oval:def:5876Security vulnerability in the RequestDispatcher class in Tomcat 5.5 bundled w...
oval:org.mitre.oval:def:10577Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6...
oval:org.mitre.oval:def:6445HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:10422Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.1...
oval:org.mitre.oval:def:5739HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:10231Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:9101Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:6628HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:6564HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:11041Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar ...
oval:org.mitre.oval:def:6450HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:10716Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:7033HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary ...

Open Source Vulnerability Database (OSVDB)

idDescription
60176Apache Tomcat Windows Installer Admin Default Password
55056Apache Tomcat Cross-application TLD File Manipulation
55055Apache Tomcat Illegally URL Encoded Password Request Username Enumeration
55054Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Heade...
55053Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
Hide | Show 11 More...
idDescription
53381Apache Tomcat JK Connector Content-Length Header Cross-user Information Discl...
52899Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp ...
49062Apache Tomcat Cross-thread Concurrent Request Variable Overwrite Information ...
47463Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
47462Apache Tomcat HttpServletResponse.sendError Method Message Argument XSS
39000Apache Tomcat SendMailServlet sendmail.jsp mailfrom Parameter XSS
37071Apache Tomcat Cookie Handling Session ID Disclosure
37070Apache Tomcat Cookie Handling Quote Delimiter Session ID Disclosure
36079Apache Tomcat Manager Uploaded Filename XSS
19821Apache Tomcat Malformed Post Request Information Disclosure
7394Apache Tomcat mod_jk Invalid Transfer-Encoding Chunked Field DoS

Metasploit Exploits

idDescription
2009-11-09Apache Tomcat Manager Application Deployer Authenticated Code Execution