← All CVEs

CVE-2010-2227

medium · 6.4

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."

6.4
CVSS
54.8%
EPSS (exploit prob.)
99th
EPSS percentile
2010-07-13
Published

AV:N/AC:L/Au:N/C:P/I:N/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
apachetomcat5.5.0
apachetomcat5.5.1
apachetomcat5.5.2
apachetomcat5.5.3
apachetomcat5.5.4
apachetomcat5.5.5
apachetomcat5.5.6
apachetomcat5.5.7
apachetomcat5.5.8
apachetomcat5.5.9
apachetomcat5.5.10
apachetomcat5.5.11
apachetomcat5.5.12
apachetomcat5.5.13
apachetomcat5.5.14
apachetomcat5.5.15
apachetomcat5.5.16
apachetomcat5.5.17
apachetomcat5.5.18
apachetomcat5.5.19
apachetomcat5.5.20
apachetomcat5.5.21
apachetomcat5.5.22
apachetomcat5.5.23
apachetomcat5.5.24
apachetomcat5.5.25
apachetomcat5.5.26
apachetomcat5.5.27
apachetomcat5.5.28
apachetomcat5.5.29
apachetomcat6.0.0
apachetomcat6.0.1
apachetomcat6.0.2
apachetomcat6.0.3
apachetomcat6.0.4
apachetomcat6.0.5
apachetomcat6.0.6
apachetomcat6.0.7
apachetomcat6.0.8
apachetomcat6.0.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-2227