← All CVEs

CVE-2014-0050

high · 7.5

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

7.5
CVSS
83.2%
EPSS (exploit prob.)
100th
EPSS percentile
2014-04-01
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
oracleretail_applications12.0
oracleretail_applications12.0in
oracleretail_applications13.0
oracleretail_applications13.1
oracleretail_applications13.2
oracleretail_applications13.3
oracleretail_applications13.4
oracleretail_applications14.0
apachecommons_fileupload<= 1.3
apachecommons_fileupload1.0
apachecommons_fileupload1.1
apachecommons_fileupload1.1.1
apachecommons_fileupload1.2
apachecommons_fileupload1.2.1
apachecommons_fileupload1.2.2
apachetomcat7.0.0
apachetomcat7.0.0
apachetomcat7.0.1
apachetomcat7.0.2
apachetomcat7.0.2
apachetomcat7.0.3
apachetomcat7.0.4
apachetomcat7.0.4
apachetomcat7.0.5
apachetomcat7.0.6
apachetomcat7.0.7
apachetomcat7.0.8
apachetomcat7.0.9
apachetomcat7.0.10
apachetomcat7.0.11
apachetomcat7.0.12
apachetomcat7.0.13
apachetomcat7.0.14
apachetomcat7.0.15
apachetomcat7.0.16
apachetomcat7.0.17
apachetomcat7.0.18
apachetomcat7.0.19
apachetomcat7.0.20
apachetomcat7.0.21

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0050