<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:08:04 +0000</lastBuildDate>
    <item>
      <title>certfr-2015-avi-204 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Apache Tomcat&lt;/span&gt;. Elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2015-avi-204</link>
      <description>certfr-2015-avi-204</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2015-avi-204</guid>
    </item>
    <item>
      <title>cnvd-2015-02909</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-02909</link>
      <description>cnvd-2015-02909</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-02909</guid>
    </item>
    <item>
      <title>EUVD-2026-96793</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-96793</link>
      <description>EUVD-2026-96793</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-96793</guid>
    </item>
    <item>
      <title>fkie_cve-2014-0230</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0230</link>
      <description>&lt;p&gt;Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-0230</guid>
    </item>
    <item>
      <title>GHSA-pxcx-cxq8-4mmw — Uncontrolled Resource Consumption in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pxcx-cxq8-4mmw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pxcx-cxq8-4mmw</guid>
    </item>
    <item>
      <title>gsd-2014-0230</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-0230</link>
      <description>gsd-2014-0230</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-0230</guid>
    </item>
    <item>
      <title>RHEA-2015:1770 — Red Hat Enhancement Advisory: Red Hat JBoss Web Server 3.0.1 enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhea-2015:1770</link>
      <description>&lt;p&gt;tomcat: non-persistent DoS attack by feeding data by aborting an upload mod_jk: information leak due to incorrect JkMount/JkUnmount directives processing openssl: X509_to_X509_REQ NULL pointer dereference&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: non-persistent DoS attack by feeding data by aborting an upload mod_jk: information leak due to incorrect JkMount/JkUnmount directives processing openssl: X509_to_X509_REQ NULL pointer dereference&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhea-2015:1770</guid>
    </item>
    <item>
      <title>RHSA-2016:2599 — Red Hat Security Advisory: tomcat security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:2599</link>
      <description>&lt;p&gt;tomcat: non-persistent DoS attack by feeding data by aborting an upload tomcat: URL Normalization issue tomcat: directory disclosure tomcat: CSRF token leak tomcat: security manager bypass via StatusManagerServlet tomcat: Security Manager bypass via persistence mechanisms tomcat: security manager bypass via setGlobalContext() tomcat: Usage of vulnerable FileUpload package can result in denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: non-persistent DoS attack by feeding data by aborting an upload tomcat: URL Normalization issue tomcat: directory disclosure tomcat: CSRF token leak tomcat: security manager bypass via StatusManagerServlet tomcat: Security Manager bypass via persistence mechanisms tomcat: security manager bypass via setGlobalContext() tomcat: Usage of vulnerable FileUpload package can result in denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:2599</guid>
    </item>
    <item>
      <title>SUSE-SU-2015:1337-1 — Security update for tomcat6</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2015:1337-1</link>
      <description>&lt;p&gt;Security update for tomcat6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2015:1337-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-0230</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0230</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat6&lt;/p&gt;
&lt;p&gt;Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat6&lt;/p&gt;
&lt;p&gt;Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0230</guid>
    </item>
  </channel>
</rss>
