Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.0
CVE-2002-0576
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request th…
Coldfusion Server
Patch available
HIGH 7.5
CVE-2002-0108
Allaire Forums 2.0.4 and 2.0.5 and Forums! 3.0 and 3.1 allows remote authenticated users to spoof messages as other users by modifying the hidden for…
Forums
Mitigation only
MEDIUM 6.4
CVE-2001-1120
Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server…
Coldfusion Server
Patch available
HIGH 10.0
CVE-1999-0760
Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.
Coldfusion Server
Patch available
HIGH 7.5
CVE-1999-0923
Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a prox…
Coldfusion Server
Patch available
MEDIUM 5.0
CVE-1999-0756
ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.
Coldfusion Server
Mitigation only
MEDIUM 5.0
CVE-1999-0800EPSS 8%
The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.
Forums
after 2.0.4
MEDIUM 5.0
CVE-1999-0922
An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.
Coldfusion Server
Patch available
MEDIUM 5.0
CVE-1999-0924
The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.
Coldfusion Server
Patch available
MEDIUM 6.4
CVE-2000-0862
Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration inf…
Spectra
Mitigation only
MEDIUM 5.0
CVE-2000-0538EPSS 8%
ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.
Coldfusion Server
Patch available
MEDIUM 5.0
CVE-2000-0410
ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not s…
Coldfusion Server
Patch available
MEDIUM 6.4
CVE-2000-0297
Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForu…
Forums
Mitigation only
MEDIUM 5.0
CVE-2000-0189
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend…
Coldfusion Server
Mitigation only
HIGH 7.5
CVE-2000-0057EPSS 6%
Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.
Coldfusion Server
Patch available
MEDIUM 5.0
CVE-2000-0051
The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexin…
Spectra
Patch available
HIGH 7.5
CVE-2000-0120
The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.
Spectra
Mitigation only
HIGH 7.5
CVE-1999-1124
HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page…
Coldfusion
Mitigation only
HIGH 7.5
CVE-1999-0455EPSS 6%
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does …
Coldfusion Server
Mitigation only
HIGH 7.5
CVE-1999-0477EPSS 5%
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not…
Coldfusion Server
Patch available