NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80960 | CVE-2002-2009 | Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
80959 | CVE-2002-2008 | Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
79931 | CVE-2002-0935 | Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
70292 | CVE-2005-4703 | Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
80347 | CVE-2002-1394 | Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View |
Page 1290 of 17672, showing 5 records out of 88360 total, starting on record 6446, ending on 6450