Search CVE reports


Toggle filters

191 – 193 of 193 results


CVE-2011-2481

Low priority

Not in release

Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web...

1 affected package

tomcat7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat7 — — — — —
Show less packages

CVE-2011-2526

Low priority

Some fixes available 4 of 5

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass...

3 affected packages

tomcat5.5, tomcat6, tomcat7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5.5 — — — — —
tomcat6 — — — — —
tomcat7 — — — — —
Show less packages

CVE-2011-2204

Low priority

Some fixes available 3 of 4

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to...

3 affected packages

tomcat5.5, tomcat6, tomcat7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat5.5 — — — — —
tomcat6 — — — — —
tomcat7 — — — — —
Show less packages