Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
https://exchange.xforce.ibmcloud.com/vulnerabilities/19681
http://www.securityfocus.com/bid/12795
http://www.kb.cert.org/vuls/id/JGEI-6A2LEF
http://www.kb.cert.org/vuls/id/204710
http://www.hitachi-support.com/security_e/vuls_e/HS05-006_e/index-e.html