Description
Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
Remediation
References
Related Vulnerabilities
WordPress Plugin W3 Total Cache Multiple Vulnerabilities (0.9.4.1)
WordPress Plugin ELEX WooCommerce Google Shopping (Google Product Feed) Cross-Site Scripting (1.2.3)
WordPress Plugin WordLift-AI powered SEO-Schema Cross-Site Scripting (3.37.1)
WordPress Plugin Eshop Magic Arbitrary File Disclosure (0.1)