← All CVEs

CVE-2014-0075

medium · 5

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remote attackers to cause a denial of service (resource consumption) via a malformed chunk size in chunked transfer coding of a request during the streaming of data.

5
CVSS
20.1%
EPSS (exploit prob.)
97th
EPSS percentile
2014-05-31
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
apachetomcat7.0.0
apachetomcat7.0.0
apachetomcat7.0.1
apachetomcat7.0.2
apachetomcat7.0.2
apachetomcat7.0.3
apachetomcat7.0.4
apachetomcat7.0.4
apachetomcat7.0.5
apachetomcat7.0.6
apachetomcat7.0.7
apachetomcat7.0.8
apachetomcat7.0.9
apachetomcat7.0.10
apachetomcat7.0.11
apachetomcat7.0.12
apachetomcat7.0.13
apachetomcat7.0.14
apachetomcat7.0.15
apachetomcat7.0.16
apachetomcat7.0.17
apachetomcat7.0.18
apachetomcat7.0.19
apachetomcat7.0.20
apachetomcat7.0.21
apachetomcat7.0.22
apachetomcat7.0.23
apachetomcat7.0.24
apachetomcat7.0.25
apachetomcat7.0.26
apachetomcat7.0.27
apachetomcat7.0.28
apachetomcat7.0.29
apachetomcat7.0.30
apachetomcat7.0.31
apachetomcat7.0.32
apachetomcat7.0.33
apachetomcat7.0.34
apachetomcat7.0.35
apachetomcat7.0.36

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0075