<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T11:32:31.099699+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certa-2008-avi-511</id>
    <title>certa-2008-avi-511 — Une vulnérabilité a été découverte dans Apache Tomcat. L'exploitation de
cette vulnérabilité permet de contourner la po…</title>
    <updated>2026-10-07T11:32:31.104121+00:00</updated>
    <content>certa-2008-avi-511</content>
    <link href="https://cve.radiocsirt.org/vuln/certa-2008-avi-511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-128364</id>
    <title>EUVD-2026-128364</title>
    <updated>2026-10-07T11:32:31.104159+00:00</updated>
    <content>EUVD-2026-128364</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-128364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2008-3271</id>
    <title>fkie_cve-2008-3271</title>
    <updated>2026-10-07T11:32:31.104175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2008-3271"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5jpg-mjvg-hfhp</id>
    <title>GHSA-5jpg-mjvg-hfhp</title>
    <updated>2026-10-07T11:32:31.104207+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5jpg-mjvg-hfhp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2008-3271</id>
    <title>gsd-2008-3271</title>
    <updated>2026-10-07T11:32:31.104226+00:00</updated>
    <content>gsd-2008-3271</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2008-3271"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2008-000069</id>
    <title>jvndb-2008-000069</title>
    <updated>2026-10-07T11:32:31.104239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat from The Apache Software Foundation contains a vulnerability which may allow a user from a non-premitted IP address to gain access.

Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.
Apache Tomcat contains a vulnerability which may allow a user from a non-permitted IP address to gain access to a protected context. 

This vulnerability was addressed and solved in ASF Bugzilla - Bug 25835. However there was no description regarding this vulnerability in ASF Bugzilla - Bug 25835. Therefore, The Apache Tomcat Development Team has decided to publish an advisory regarding this issue. 

Kenichi Tsukamoto of Development Dept. II Application Management Middleware Div. FUJITSU LIMITED reported this vulnerability to IPA.
JPCERT/CC coordinated with The Apache Software Foundation and the vendors under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2008-000069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2008:1007</id>
    <title>RHSA-2008:1007 — Red Hat Security Advisory: tomcat security update for Red Hat Network Satellite Server</title>
    <updated>2026-10-07T11:32:31.104261+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: Cross-Site-Scripting enabled by sendError call Tomcat host manager xss - name field tomcat RequestDispatcher information disclosure vulnerability tomcat Unicode directory traversal vulnerability tomcat  RemoteFilterValve Information disclosure</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2008:1007"/>
  </entry>
</feed>
