CVE-2005-3510

Aliases:GHSA-8f4w-jwqv-5cxc
Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 06 Nov 2005, 11:00
Last modified:07 Aug 2024, 23:17

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
20.51% HIGH
21% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Nov 2005, 11:00
Published
Vulnerability first disclosed
07 Aug 2024, 23:17
Last Modified
Vulnerability information updated

Description

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 20.51% Percentile: 96%

Affected Systems

  • UnknownTomcat

    5.5.0 | 5.5.1 | 5.5.2 | 5.5.3 | 5.5.4 | 5.5.5 | 5.5.6 | 5.5.7 | 5.5.8 | 5.5.9 | 5.5.10 | 5.5.11

  • org.apache.tomcattomcat

    ≥ 5.5.0, < 5.5.12

References (32)