cbcvebase.
CVE-2014-0050
published 2014-04-01

CVE-2014-0050: MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
EXPLOIT
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

Affected

70 ranges· showing 25
VendorProductVersion rangeFixed in
apachecommons_fileupload<= 1.3
apachecommons_fileupload
apachecommons_fileupload
apachecommons_fileupload
apachecommons_fileupload
apachecommons_fileupload
apachecommons_fileupload
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH