Description
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Symposium Pro Social Network Cross-Site Scripting (16.01)
Perl Out-of-bounds Write Vulnerability (CVE-2018-6797)
Oracle HTTP Server Out-of-bounds Write Vulnerability (CVE-2022-23943)
WordPress Plugin Auto Featured Image Arbitrary File Upload (1.2)
WordPress Plugin Widget Settings Importer/Exporter Cross-Site Scripting (1.5.3)