{"id":"CVE-2014-0095","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-0095","summary":"Denial of service in Apache Tomcat","details":"java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a \"Content-Length: 0\" AJP request to trigger a hang in request processing.","published":"2022-05-17T00:24:30Z","modified":"2024-11-28T05:36:07.555519Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-coyote","fixedVersion":"8.0.4"},{"ecosystem":"Maven","name":"org.apache.tomcat.embed:tomcat-embed-core","fixedVersion":"8.0.4"}],"fix":{"url":"https://github.com/apache/tomcat/commit/8884dae60ace77a87ed9385442ce429e98c3a479","label":"apache/tomcat@8884dae"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0095"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/8884dae60ace77a87ed9385442ce429e98c3a479"},{"type":"WEB","url":"https://github.com/apache/tomcat80/commit/77590c897f0e542fe363d70efdf3b82209510aee"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://web.archive.org/web/20140713043210/http://www.securitytracker.com/id/1030300"},{"type":"WEB","url":"https://web.archive.org/web/20141126170141/http://www.securityfocus.com/bid/67673"},{"type":"WEB","url":"https://web.archive.org/web/20151017043748/http://secunia.com/advisories/60729"},{"type":"WEB","url":"https://web.archive.org/web/20161024215453/http://secunia.com/advisories/59873"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2014/May/134"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=1578392"},{"type":"WEB","url":"http://tomcat.apache.org/security-8.html"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21678231"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21681528"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:36:07.555519Z"}}