Skip to main content

Vendor/product archive

redhat / jboss_enterprise_web_server CVEs

Beta · best-effort

34 CVEs tagged to redhat / jboss_enterprise_web_server7 Critical, 17 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2018-1336

Published Aug 2, 2018

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apac…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2018-1304

Published Feb 28, 2018

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49…

CVSS 5.9 · Medium

CVE-2017-12613

Published Oct 24, 2017

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be acce…

CVSS 7.1 · High

CVE-2016-6325

Published Oct 13, 2016

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/to…

CVSS 7.8 · High
Showing 1-25 of 34 CVEsPage 1 of 2