Skip to main content

CVE detail

CVE-2003-0866

The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.

CVSS 5.0 · MediumBuzz score 12.03 OTX pulses

Buzz score

Why this CVE is surfacing

Buzz score total 12.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 0.0 · diversity 0.0 · KEV 0.0 · OTX 12.0 · PoC 0.0
Mention score
0.0
0 evidence mentions in the snapshot
Diversity score
0.0
0 sources across 0 categories
KEV score
0.0
No KEV entry observed
OTX score
12.0
3 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
0 source links · newest first

    Exploit code

    Public exploit repository references

    Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

    0 repository references · best confidence N/A · max 0 stars
    No public PoC repositories have been matched yet.

    Related records

    Similar CVEs

    6 related CVEs with shared weakness or product evidence
    • CVE-2026-66299

      Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through…

      CVSS 7.5 · High
      2 mentions
    • CVE-2026-59084

      Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue af…

      CVSS 9.1 · Critical
      3 mentions
    • CVE-2026-59083

      Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apa…

      CVSS 9.1 · Critical
      Public PoC observed2 mentions
    • CVE-2026-55957

      Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate witho…

      CVSS 7.3 · High
      2 mentions
    • CVE-2026-55956

      Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of…

      CVSS 6.5 · Medium
      2 mentions
    • CVE-2026-55955

      Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from…

      CVSS 6.5 · Medium
      2 mentions