CVE-2014-0050
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
- Affected products
- Alt Linux, Apache Commons Fileupload, Apache Struts, Apache Tomcat, Centos, Red Hat, Suse, Vmware Vcenter
- Oracle Retail Applications
- = 12.0, 12.0in, 13.0, 13.1, 13.2, 13.3, 13.4, 14.0
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 83.2% (100th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2014-03-28
CVE-2014-0050 at NVD
7 known exploits for CVE-2014-0050
Proof-of-concept code and exploit modules indexed by Sploitus
Apache Commons FileUpload and Apache Tomcat Denial of Service
Apache Commons FileUpload and Apache Tomcat - Denial-of-Service
Apache Commons FileUpload and Apache Tomcat DoS
Apache Commons FileUpload/Apache Tomcat拒绝服务漏洞
Apache Commons FileUpload and Apache Tomcat Denial of Service
Apache Commons FileUpload and Apache Tomcat - Denial of Service
Apache Commons FileUpload and Apache Tomcat - Denial of Service