Apache Tomcat Resource Management Errors Vulnerability - CVE-2011-0534
Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
