This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:apache:tomcat:4.1.32
Detail
VendorApacheFirst view 2005-12-31
ProductTomcatLast view 2009-11-12
Version4.1.32TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:apache:tomcat

Activity : Yearly

Related : CVE

 DateAlertAccess VectorAccess ComplexityAuthentification
7.52009-11-12CVE-2009-3548NetworkLowNone Requ...
52009-06-16CVE-2008-5515NetworkLowNone Requ...
4.62009-06-05CVE-2009-0783LocalLowNone Requ...
4.32009-06-05CVE-2009-0580NetworkMediumNone Requ...
52009-06-05CVE-2009-0033NetworkLowNone Requ...
Hide | Show 5 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
2.62009-04-09CVE-2008-5519NetworkHighNone Requ...
4.32009-03-09CVE-2009-0781NetworkMediumNone Requ...
2.62009-02-26CVE-2008-4308NetworkHighNone Requ...
52008-08-03CVE-2008-2370NetworkLowNone Requ...
7.82005-12-31CVE-2005-4836NetworkLowNone Requ...

CWE : Common Weakness Enumeration

%idName
50% (5)CWE-200Information Exposure
20% (2)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path ...
10% (1)CWE-255Credentials Management
10% (1)CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
10% (1)CWE-20Improper Input Validation

Oval Markup Language : Definitions

OvalIDName
oval:org.mitre.oval:def:5876Security vulnerability in the RequestDispatcher class in Tomcat 5.5 bundled w...
oval:org.mitre.oval:def:10577Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6...
oval:org.mitre.oval:def:6445HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:10422Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.1...
oval:org.mitre.oval:def:5739HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
Hide | Show 8 More...
idName
oval:org.mitre.oval:def:10231Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:9101Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:6628HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:6564HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:11041Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar ...
oval:org.mitre.oval:def:6450HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:10716Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:7033HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary ...

Open Source Vulnerability Database (OSVDB)

idDescription
60176Apache Tomcat Windows Installer Admin Default Password
55056Apache Tomcat Cross-application TLD File Manipulation
55055Apache Tomcat Illegally URL Encoded Password Request Username Enumeration
55054Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Heade...
55053Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
Hide | Show 5 More...
idDescription
53381Apache Tomcat JK Connector Content-Length Header Cross-user Information Discl...
52899Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp ...
52407Apache Tomcat doRead Method POST Content Information Disclosure
47463Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
34880Apache Tomcat HTTP/1.1 Connector NULL Byte Request JSP Source Disclosure

Metasploit Exploits

idDescription
2009-11-09Apache Tomcat Manager Application Deployer Authenticated Code Execution