CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2....Show more |
2Apache Debian2Commons Fileupload Debian LinuxJun 17, 2026 Feb 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, li...Show more |
1Apache 1Commons Fileupload May 6, 2026 Oct 25, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution |
4Apache CanonicalDebian+1 more6Commons Fileupload Debian LinuxIcewall Identity Manager+3 moreMay 6, 2026 Jul 4, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers...Show more |
2Apache Oracle3Commons Fileupload Retail ApplicationsTomcatMay 6, 2026 Apr 1, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a craf...Show more |
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecifi...Show more |