Macromedia / Coldfusion
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2003-1469 | The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path… | MEDIUM | 5.0 | Oct 24, 2007 |
| CVE-2006-3979 | The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Administrato… | HIGH | 7.2 | Aug 9, 2006 |
| CVE-2006-2364 | Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary web scrip… | MEDIUM | 5.8 | May 15, 2006 |
| CVE-2005-4345 | Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash a… | HIGH | 7.2 | Dec 17, 2005 |
| CVE-2005-4344 | Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an o… | LOW | 2.1 | Dec 17, 2005 |
| CVE-2005-4343 | Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subjec… | MEDIUM | 5.0 | Dec 17, 2005 |
| CVE-2005-4342 | ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled… | HIGH | 7.5 | Dec 17, 2005 |
| CVE-2004-2505 | Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumptio… | MEDIUM | 5.0 | Oct 25, 2005 |
| CVE-2004-2331 | ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to… | MEDIUM | 5.5 | Aug 16, 2005 |
| CVE-2004-2330 | ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a large number of form fields. | MEDIUM | 5.0 | Aug 16, 2005 |
| CVE-2005-2306 | Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple ses… | LOW | 3.7 | Jul 19, 2005 |
| CVE-2002-1992 | Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template fi… | MEDIUM | 5.0 | Jul 14, 2005 |
| CVE-2001-1514 | ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1)… | HIGH | 10.0 | Jul 14, 2005 |
| CVE-2004-2204 | Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct una… | HIGH | 7.2 | Jul 10, 2005 |
| CVE-2002-1700 | Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as oth… | MEDIUM | 4.3 | Jun 21, 2005 |
| CVE-2005-1555 | Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, wh… | MEDIUM | 4.3 | May 14, 2005 |
| CVE-2004-1815 | Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers t… | MEDIUM | 5.0 | May 10, 2005 |
| CVE-2004-0928 | The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source fi… | MEDIUM | 5.0 | Apr 21, 2005 |
| CVE-2005-1022 | ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive inf… | MEDIUM | 5.0 | Apr 9, 2005 |
| CVE-2001-1427 | Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors. | HIGH | 7.5 | Mar 22, 2005 |
| CVE-2004-1478 | JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP sess… | HIGH | 7.5 | Feb 13, 2005 |
| CVE-2004-0646 | Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose log… | HIGH | 10.0 | Nov 19, 2004 |
| CVE-2004-0407 | The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial o… | LOW | 2.6 | Apr 17, 2004 |
| CVE-2002-1309 | Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary… | HIGH | 7.5 | Nov 21, 2002 |
Showing 1 to 24 of 24 CVEs