NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
38183  CVE-2013-2071  java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.    2.6  Low  2017-05-27  2017-05-22  View
53543  CVE-2007-1358  Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".    2.6  Low  2017-01-07  2013-07-22  View
60455  CVE-2006-1750  Multiple cross-site scripting (XSS) vulnerabilities in index.php in Autogallery 0.41 allow remote attackers to inject arbitrary web script or HTML via the (1) pic or (2) show parameters.    2.6  Low  2016-12-20  2011-09-13  View
61991  CVE-2006-3313  Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.    2.6  Low  2016-12-20  2008-09-05  View
4136  CVE-2008-4308  The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.    2.6  Low  2017-01-03  2009-02-27  View

Page 15263 of 17672, showing 5 records out of 88360 total, starting on record 76311, ending on 76315

Actions