Description
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
Remediation
References
Related Vulnerabilities
PostgreSQL CVE-2024-10976 Vulnerability (CVE-2024-10976)
WordPress Plugin Relevanssi-A Better Search 'Seach Query' Field HTML Injection (2.7.2)
MySQL CVE-2024-21055 Vulnerability (CVE-2024-21055)
WordPress Plugin LearnPress-WordPress LMS Security Bypass (3.2.6.8)
Oracle Application Server CVE-2010-0067 Vulnerability (CVE-2010-0067)