CVE-2002-2272

Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.

Scoring

CVSS base score
1.16
EPSS probability
23.16%
Published
2007-10-18
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs