← All CVEs

CVE-2018-1336

high · 7.5

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

7.5
CVSS
20.6%
EPSS (exploit prob.)
97th
EPSS percentile
2018-08-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-835

Affected products

VendorProductAffected versions
apachetomcat>= 7.0.28, <= 7.0.86
apachetomcat>= 8.0.0, <= 8.0.51
apachetomcat>= 8.5.0, <= 8.5.30
apachetomcat>= 9.0.1, <= 9.0.7
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
redhatjboss_enterprise_application_platform6.0.0
redhatjboss_enterprise_application_platform6.4.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
debiandebian_linux8.0
debiandebian_linux9.0
redhatjboss_enterprise_web_server3.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-1336