Vulnerability & Exploit Database

Displaying entries 1 - 10 of 28 in total

Results for: CVE-2018-4281 Back to search

SUSE: CVE-2018-8037: SUSE Linux Security Advisory Vulnerability

  • Severity: 4
  • Published: August 02, 2018

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection...

Red Hat: CVE-2018-1336: Important: tomcat security update (RHSA-2018:2921) Vulnerability

  • Severity: 5
  • Published: August 02, 2018

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Oracle Solaris 11: CVE-2018-8037: Vulnerability in Apache Tomcat Vulnerability

  • Severity: 4
  • Published: August 02, 2018

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection...

Oracle Solaris 11: CVE-2018-1336: Vulnerability in Apache Tomcat Vulnerability

  • Severity: 5
  • Published: August 02, 2018

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Huawei EulerOS: CVE-2018-1336: tomcat security update Vulnerability

  • Severity: 5
  • Published: August 02, 2018

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Huawei EulerOS: CVE-2018-1336: tomcat security update Vulnerability

  • Severity: 5
  • Published: August 02, 2018

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Debian: CVE-2018-8037: tomcat8 -- security update Vulnerability

  • Severity: 4
  • Published: August 02, 2018

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection...

SUSE: CVE-2018-8034: SUSE Linux Security Advisory Vulnerability

  • Severity: 5
  • Published: August 01, 2018

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

Oracle Solaris 11: CVE-2018-8034: Vulnerability in Apache Tomcat Vulnerability

  • Severity: 5
  • Published: August 01, 2018

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

Debian: CVE-2018-8034: tomcat7, tomcat8 -- security update Vulnerability

  • Severity: 5
  • Published: August 01, 2018

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.