VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 50 minutes ago
Reset
More filters (3)
Columns
EPSS ≥ 0.5Published from 2007-01-01Published to 2007-12-31
Overview 4 matches, all in RASP scope, all public PoC, all EPSS ≥ 0.5 · 0 protected · 0 KEV · 0 CISA SSVC · 0 disputed
4matches, all in RASP scope, all public PoC, all EPSS ≥ 0.5 0protected0.0% 0KEV0.0% 0CISA SSVC0.0% 0disputed0.0%
Critical 0 0.0% High 0 0.0% Medium 4 100.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 4 100.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 0 0.0% not blocked 4 100.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 4 100.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 0 0.0%
split by peak 2 / month
Unknown: 0None: 0Low: 0Medium: 4High: 0Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 0Mitigation candidate: 4Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 4blocked by ARMR today: 0 No public exploit: 0Forecast only: 0Proof of concept only: 0Working exploit published: 4Exploited in the wild: 0 May 2007: 2 CVEs June 2007: 1 CVE July 2007: 0 CVEs August 2007: 1 CVE
May 07Jun 07Jul 07Aug 07
4 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2007-3386 Medium 2007-08-14 Mitigation candidate Working exploit published Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
CVE-2007-2449 Medium 2007-06-14 Mitigation candidate Working exploit published Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.
CVE-2007-1355 Medium 2007-05-21 Mitigation candidate Working exploit published Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
CVE-2006-7196 Medium 2007-05-10 Mitigation candidate Working exploit published Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.