<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:12:26.267693+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certa-2009-avi-211</id>
    <title>certa-2009-avi-211 — Plusieurs vulnérabilités présentes dans Apache Tomcat permettent à un
utilisateur distant de provoquer un déni de servi…</title>
    <updated>2026-10-03T08:12:26.392942+00:00</updated>
    <content>certa-2009-avi-211</content>
    <link href="https://cve.radiocsirt.org/vuln/certa-2009-avi-211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-130385</id>
    <title>EUVD-2026-130385</title>
    <updated>2026-10-03T08:12:26.392986+00:00</updated>
    <content>EUVD-2026-130385</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-130385"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2008-5515</id>
    <title>fkie_cve-2008-5515</title>
    <updated>2026-10-03T08:12:26.393008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2008-5515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9737-qmgc-hfr9</id>
    <title>GHSA-9737-qmgc-hfr9 — Directory Traversal in Apache Tomcat</title>
    <updated>2026-10-03T08:12:26.393053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9737-qmgc-hfr9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2008-5515</id>
    <title>gsd-2008-5515</title>
    <updated>2026-10-03T08:12:26.393091+00:00</updated>
    <content>gsd-2008-5515</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2008-5515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2009-000036</id>
    <title>jvndb-2009-000036</title>
    <updated>2026-10-03T08:12:26.393105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat from The Apache Software Foundation contains an information disclosure vulnerability.

Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.
Apache Tomcat contains a vulnerability which may allow information disclosure or access to the contents contained in the WEB-INF directory.

According to the developer, unsupported Apache Tomcat 3.x, 4.0.x, and 5.0.x may also be affected.
For more information, refer to the developer's website.

Minehiko Iida and Yuichiro Suzuki of Development Dept. II Application Management Middleware Div. FUJITSU LIMITED reported this vulnerability to IPA. JPCERT/CC coordinated with The Apache Software Foundation and the vendors under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2009-000036"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2009:1143</id>
    <title>RHSA-2009:1143 — Red Hat Security Advisory: JBoss Enterprise Application Platform 4.2.0.CP07 update</title>
    <updated>2026-10-03T08:12:26.393129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat request dispatcher information disclosure vulnerability tomcat6 Information disclosure in authentication classes tomcat XML parser information disclosure</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2009:1143"/>
  </entry>
</feed>
