<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:12:26 +0000</lastBuildDate>
    <item>
      <title>certa-2009-avi-211 — Plusieurs vulnérabilités présentes dans Apache Tomcat permettent à un
utilisateur distant de provoquer un déni de servi…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2009-avi-211</link>
      <description>certa-2009-avi-211</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2009-avi-211</guid>
    </item>
    <item>
      <title>EUVD-2026-130385</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-130385</link>
      <description>EUVD-2026-130385</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-130385</guid>
    </item>
    <item>
      <title>fkie_cve-2008-5515</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2008-5515</link>
      <description>&lt;p&gt;Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2008-5515</guid>
    </item>
    <item>
      <title>GHSA-9737-qmgc-hfr9 — Directory Traversal in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9737-qmgc-hfr9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9737-qmgc-hfr9</guid>
    </item>
    <item>
      <title>gsd-2008-5515</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2008-5515</link>
      <description>gsd-2008-5515</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2008-5515</guid>
    </item>
    <item>
      <title>jvndb-2009-000036</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2009-000036</link>
      <description>&lt;p&gt;Apache Tomcat from The Apache Software Foundation contains an information disclosure vulnerability.&#13;
&#13;
Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.&#13;
Apache Tomcat contains a vulnerability which may allow information disclosure or access to the contents contained in the WEB-INF directory.&#13;
&#13;
According to the developer, unsupported Apache Tomcat 3.x, 4.0.x, and 5.0.x may also be affected.&#13;
For more information, refer to the developer&amp;#39;s website.&#13;
&#13;
Minehiko Iida and Yuichiro Suzuki of Development Dept. II Application Management Middleware Div. FUJITSU LIMITED reported this vulnerability to IPA. JPCERT/CC coordinated with The Apache Software Foundation and the vendors under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat from The Apache Software Foundation contains an information disclosure vulnerability.&#13;
&#13;
Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.&#13;
Apache Tomcat contains a vulnerability which may allow information disclosure or access to the contents contained in the WEB-INF directory.&#13;
&#13;
According to the developer, unsupported Apache Tomcat 3.x, 4.0.x, and 5.0.x may also be affected.&#13;
For more information, refer to the developer&amp;#39;s website.&#13;
&#13;
Minehiko Iida and Yuichiro Suzuki of Development Dept. II Application Management Middleware Div. FUJITSU LIMITED reported this vulnerability to IPA. JPCERT/CC coordinated with The Apache Software Foundation and the vendors under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2009-000036</guid>
    </item>
    <item>
      <title>RHSA-2009:1143 — Red Hat Security Advisory: JBoss Enterprise Application Platform 4.2.0.CP07 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2009:1143</link>
      <description>&lt;p&gt;tomcat request dispatcher information disclosure vulnerability tomcat6 Information disclosure in authentication classes tomcat XML parser information disclosure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat request dispatcher information disclosure vulnerability tomcat6 Information disclosure in authentication classes tomcat XML parser information disclosure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2009:1143</guid>
    </item>
  </channel>
</rss>
