<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:55:11.731129+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2015-avi-204</id>
    <title>certfr-2015-avi-204 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Apache Tomcat&lt;/span&gt;. Elles permettent à un att…</title>
    <updated>2026-10-03T04:55:12.061679+00:00</updated>
    <content>certfr-2015-avi-204</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2015-avi-204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2015-02909</id>
    <title>cnvd-2015-02909</title>
    <updated>2026-10-03T04:55:12.061730+00:00</updated>
    <content>cnvd-2015-02909</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2015-02909"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-96793</id>
    <title>EUVD-2026-96793</title>
    <updated>2026-10-03T04:55:12.061746+00:00</updated>
    <content>EUVD-2026-96793</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-96793"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0230</id>
    <title>fkie_cve-2014-0230</title>
    <updated>2026-10-03T04:55:12.061758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-0230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pxcx-cxq8-4mmw</id>
    <title>GHSA-pxcx-cxq8-4mmw — Uncontrolled Resource Consumption in Apache Tomcat</title>
    <updated>2026-10-03T04:55:12.061786+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pxcx-cxq8-4mmw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-0230</id>
    <title>gsd-2014-0230</title>
    <updated>2026-10-03T04:55:12.061812+00:00</updated>
    <content>gsd-2014-0230</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-0230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2015:1770</id>
    <title>RHEA-2015:1770 — Red Hat Enhancement Advisory: Red Hat JBoss Web Server 3.0.1 enhancement update</title>
    <updated>2026-10-03T04:55:12.061824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: non-persistent DoS attack by feeding data by aborting an upload mod_jk: information leak due to incorrect JkMount/JkUnmount directives processing openssl: X509_to_X509_REQ NULL pointer dereference</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2015:1770"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:2599</id>
    <title>RHSA-2016:2599 — Red Hat Security Advisory: tomcat security, bug fix, and enhancement update</title>
    <updated>2026-10-03T04:55:12.061844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: non-persistent DoS attack by feeding data by aborting an upload tomcat: URL Normalization issue tomcat: directory disclosure tomcat: CSRF token leak tomcat: security manager bypass via StatusManagerServlet tomcat: Security Manager bypass via persistence mechanisms tomcat: security manager bypass via setGlobalContext() tomcat: Usage of vulnerable FileUpload package can result in denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:2599"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2015:1337-1</id>
    <title>SUSE-SU-2015:1337-1 — Security update for tomcat6</title>
    <updated>2026-10-03T04:55:12.061874+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat6</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2015:1337-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0230</id>
    <title>UBUNTU-CVE-2014-0230</title>
    <updated>2026-10-03T04:55:12.061893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat6</p>
<p>Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0230"/>
  </entry>
</feed>
