Macromedia / Jrun
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2005-4473 | Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source code via "a malformed URL." | MEDIUM | 5.0 | Dec 22, 2005 |
| CVE-2005-4472 | Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code… | HIGH | 7.5 | Dec 22, 2005 |
| CVE-2002-2187 | Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact. | MEDIUM | 5.0 | Nov 16, 2005 |
| CVE-2002-2186 | Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL. | MEDIUM | 5.0 | Nov 16, 2005 |
| CVE-2005-2306 | Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple ses… | LOW | 3.7 | Jul 19, 2005 |
| CVE-2001-1545 | Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers… | MEDIUM | 5.0 | Jul 14, 2005 |
| CVE-2001-1544 | Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in… | MEDIUM | 5.0 | Jul 14, 2005 |
| CVE-2001-1513 | Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the we… | HIGH | 7.5 | Jul 14, 2005 |
| CVE-2001-1512 | Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Page… | MEDIUM | 6.4 | Jul 14, 2005 |
| CVE-2001-1511 | JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL contai… | MEDIUM | 5.0 | Jul 14, 2005 |
| CVE-2001-1510 | Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to r… | MEDIUM | 5.0 | Jul 14, 2005 |
| CVE-2004-2182 | Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by th… | HIGH | 7.5 | Jul 10, 2005 |
| CVE-2002-1855 | Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files a… | MEDIUM | 5.0 | Jun 28, 2005 |
| CVE-2004-1815 | Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers t… | MEDIUM | 5.0 | May 10, 2005 |
| CVE-2004-0928 | The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source fi… | MEDIUM | 5.0 | Apr 21, 2005 |
| CVE-2004-1478 | JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP sess… | HIGH | 7.5 | Feb 13, 2005 |
| CVE-2004-1477 | Cross-site scripting (XSS) vulnerability in the Management Console in JRun 4.0 allows remote attackers to execute arbitrary web script or HTML and possibly hij… | MEDIUM | 4.3 | Feb 13, 2005 |
| CVE-2004-0646 | Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose log… | HIGH | 10.0 | Nov 19, 2004 |
| CVE-2002-1025 | JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP… | MEDIUM | 5.0 | Apr 2, 2003 |
| CVE-2002-0801 | Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a lon… | HIGH | 10.0 | Apr 2, 2003 |
| CVE-2002-0665 | Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL. | HIGH | 10.0 | Apr 2, 2003 |
| CVE-2002-1310 | Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbi… | HIGH | 7.5 | Nov 21, 2002 |
| CVE-2002-0937 | The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrin… | MEDIUM | 5.0 | Aug 31, 2002 |
| CVE-2001-1084 | Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jru… | HIGH | 7.5 | Jun 25, 2002 |
| CVE-2001-0926 | SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an… | MEDIUM | 5.0 | Feb 2, 2002 |
Showing 1 to 25 of 33 CVEs