Known vulnerabilities in tomcat8 (Debian package) 8.5.37-1~bpo9+1
Vendor:
Debian
Software:
tomcat8 (Debian package)
Version:
8.5.37-1~bpo9+1
Software CPE:
cpe:2.3:o:debian:tomcat8_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
3
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
8.5.54-0+deb9u2
8.5.54-0+deb9u3
8.5.54-0+deb9u4
8.5.54-0+deb9u5
8.5.54-0+deb9u6
8.5.54-0+deb9u7
8.5.54-0+deb9u8
8.5.54
8.0.14-1+deb8u17
8.5.54-0+deb9u1
8.5.50
8.5.39
8.5.38
8.0.14
8.0.14-1+deb8u16
8.5.50-0+deb9u1
8.0.14-1+deb8u15
8.5.39-1
8.5.38-2~bpo9+1
8.5.38-2
8.5.38-1~bpo9+1
8.5.38-1
8.5.37-2
8.5.37-1~bpo9+1
8.5.37-1
8.5.35-3
8.5.35-2~bpo9+1
8.5.35-2
8.5.35-1
8.0.14-1+deb8u14
8.5.34-1~bpo9+1
8.0.9-1~bpo70+1
8.0.14-1+deb8u12
8.0.14-1+deb8u13
8.0.24-1~bpo8+1
8.0.28-1~bpo8+1
8.0.30-1~bpo8+1
8.0.32-1~bpo8+1
8.0.36-3~bpo8+1
8.0.37-1~bpo8+1
8.0.38-1~bpo8+1
8.0.38-2~bpo8+1
8.0.39-1~bpo8+1
8.5.9-1~bpo7+1
8.5.9-1~bpo8+1
8.5.11-2~bpo8+1
8.5.12-1~bpo8+1
8.5.14-1+deb9u3
8.5.24-2~bpo9+1
8.5.28-1~bpo9+1
8.5.31-1
8.5.32-1
8.5.32-2
8.5.33-1~bpo9+1
8.5.33-1
8.5.34-1
8.5.30-1
8.5.29-1~bpo9+1
8.5.29-1
8.5.28-1
8.5.24-2
8.5.24-1
8.5.23-1
8.5.21-1
8.5.14-1+deb9u2
8.0.14-1+deb8u11
8.5.11-1~bpo8+1
8.5.11-1~bpo8+2
8.5.11-1~bpo7+1
8.0.14-1~bpo70+1
8.0.14-1~bpo70+2
8.5.14-2
8.5.15-1
8.5.16-1
8.5.14-1+deb9u1
8.0.14-1+deb8u1
8.0.14-1+deb8u2
8.0.14-1+deb8u3
8.0.14-1+deb8u4
8.0.14-1+deb8u5
8.0.14-1+deb8u6
8.0.14-1+deb8u7
8.0.14-1+deb8u8
8.0.14-1+deb8u9
8.0.14-1+deb8u10
8.5.8-2
8.5.9-1
8.5.9-2
8.5.11-1
8.5.11-2
8.5.12-1
8.5.14-1
8.5.14-1~bpo8+1
8.0.3-1
8.0.5-1
8.0.8-1
8.0.9-1
8.0.12-1
8.0.14-1
8.0.15-1
8.0.17-1
8.0.18-1
8.0.21-1
8.0.21-2
8.0.22-1
8.0.22-2
8.0.23-1
8.0.24-1
8.0.26-1
8.0.28-1
8.0.30-1
8.0.32-1
8.0.36-1
8.0.36-2
8.0.36-3
8.0.37-1
8.0.38-1
8.0.38-2
8.0.39-1
8.5.8-1
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU25807 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-1935 |
CWE-444 | Medium | 8.5.54-0+deb9u1 | 06.03.2020 |
SB2020022111 SB2020031401 SB2020031402 and 15 more |
||
| #VU25806 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2019-17569 |
CWE-444 | Medium | 8.5.54-0+deb9u1 | 06.03.2020 |
SB2020022111 SB2020031401 SB2020031402 and 6 more |
||
| #VU25502 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-1938 |
CWE-22 | High | 8.5.54-0+deb9u1 | 21.02.2020 |
SB2020022111 SB2020031401 SB2020031402 and 31 more |