Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2014-0050

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
Software From Fixed in
oracle / retail_applications 12.0in 12.0in.x
oracle / retail_applications 13.0 13.0.x
oracle / retail_applications 13.3 13.3.x
oracle / retail_applications 13.2 13.2.x
oracle / retail_applications 12.0 12.0.x
oracle / retail_applications 14.0 14.0.x
oracle / retail_applications 13.1 13.1.x
oracle / retail_applications 13.4 13.4.x
apache / tomcat 7.0.2-beta 7.0.2-beta.x
apache / tomcat 7.0.49 7.0.49.x
apache / tomcat 7.0.12 7.0.12.x
apache / tomcat 7.0.20 7.0.20.x
apache / tomcat 7.0.34 7.0.34.x
apache / tomcat 7.0.8 7.0.8.x
apache / tomcat 7.0.1 7.0.1.x
apache / tomcat 7.0.2 7.0.2.x
apache / tomcat 7.0.5 7.0.5.x
apache / commons_fileupload 1.2.2 1.2.2.x
apache / tomcat 7.0.4-beta 7.0.4-beta.x
apache / tomcat 7.0.22 7.0.22.x
apache / tomcat 7.0.39 7.0.39.x
apache / tomcat 7.0.26 7.0.26.x
apache / tomcat 7.0.46 7.0.46.x
apache / tomcat 7.0.28 7.0.28.x
apache / tomcat 8.0.1 8.0.1.x
apache / tomcat 7.0.0 7.0.0.x
apache / commons_fileupload 1.2 1.2.x
apache / tomcat 7.0.50 7.0.50.x
apache / tomcat 7.0.6 7.0.6.x
apache / commons_fileupload 1.1 1.1.x
apache / tomcat 8.0.0-rc2 8.0.0-rc2.x
apache / tomcat 7.0.18 7.0.18.x
apache / tomcat 7.0.14 7.0.14.x
apache / tomcat 7.0.48 7.0.48.x
apache / tomcat 7.0.11 7.0.11.x
apache / tomcat 8.0.0-rc1 8.0.0-rc1.x
apache / tomcat 7.0.23 7.0.23.x
apache / tomcat 7.0.0-beta 7.0.0-beta.x
apache / tomcat 7.0.44 7.0.44.x
apache / tomcat 7.0.7 7.0.7.x
apache / tomcat 7.0.42 7.0.42.x
apache / tomcat 7.0.37 7.0.37.x
apache / tomcat 7.0.29 7.0.29.x
apache / tomcat 7.0.45 7.0.45.x
apache / commons_fileupload - 1.3.x
apache / tomcat 8.0.0-rc10 8.0.0-rc10.x
apache / tomcat 7.0.13 7.0.13.x
apache / tomcat 7.0.47 7.0.47.x
apache / tomcat 7.0.41 7.0.41.x
apache / tomcat 7.0.31 7.0.31.x
apache / tomcat 7.0.30 7.0.30.x
apache / tomcat 7.0.15 7.0.15.x
apache / tomcat 7.0.19 7.0.19.x
apache / tomcat 7.0.16 7.0.16.x
apache / tomcat 7.0.10 7.0.10.x
apache / commons_fileupload 1.1.1 1.1.1.x
apache / tomcat 7.0.36 7.0.36.x
apache / tomcat 7.0.25 7.0.25.x
apache / tomcat 7.0.35 7.0.35.x
apache / tomcat 7.0.43 7.0.43.x
apache / tomcat 8.0.0-rc5 8.0.0-rc5.x
apache / tomcat 7.0.32 7.0.32.x
apache / tomcat 7.0.38 7.0.38.x
apache / tomcat 7.0.21 7.0.21.x
apache / tomcat 7.0.27 7.0.27.x
apache / commons_fileupload 1.2.1 1.2.1.x
apache / tomcat 7.0.24 7.0.24.x
apache / tomcat 7.0.17 7.0.17.x
apache / tomcat 7.0.40 7.0.40.x
apache / tomcat 7.0.9 7.0.9.x
apache / commons_fileupload 1.0 1.0.x
apache / tomcat 7.0.4 7.0.4.x
apache / tomcat 7.0.3 7.0.3.x
apache / tomcat 7.0.33 7.0.33.x
commons-fileupload / commons-fileupload - 1.3.1