Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2007-1403EPSS 29% Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial o… Shockwave No fix yet Fix from $1,9502007-03-10 MEDIUM 5.0 CVE-2006-6827 Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.A… Flash Player No fix yet Fix from $1,6002006-12-31 MEDIUM 5.8 CVE-2006-2364 Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary… Coldfusion No fix yet Fix from $1,6002006-05-15 HIGH 7.8 CVE-2005-4216 The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (applicatio… Flash Media Server No fix yet Fix from $1,9502005-12-14 MEDIUM 5.0 CVE-2005-2481 ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server pat… Coldfusion Fusebox Mitigation only Fix from $1,6002005-08-05 HIGH 7.5 CVE-2004-2182 Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information … Jrun Mitigation only Fix from $1,9502004-12-31 HIGH 7.2 CVE-2004-2204 Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to c… Coldfusion Mitigation only Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2003-1469EPSS 6% The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the… Coldfusion No fix yet Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2002-1534 Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share. Flash Player No fix yet Fix from $1,6002003-03-31 MEDIUM 5.0 CVE-2002-1881 Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a … Flash Player No fix yet Fix from $1,6002002-12-31 HIGH 7.5 CVE-2002-1382 Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file … Flash Player Mitigation only Fix from $1,9502002-12-23 HIGH 7.5 CVE-2002-1027 Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attacker… Sitespring No fix yet Fix from $1,9502002-10-04 MEDIUM 5.0 CVE-2002-0937EPSS 7% The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that c… Jrun No fix yet Fix from $1,6002002-10-04 MEDIUM 5.0 CVE-2002-1026 Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long ma… Sitespring No fix yet Fix from $1,6002002-10-04 HIGH 7.5 CVE-2002-0846 The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than … Shockwave Flash Mitigation only Fix from $1,9502002-08-12 HIGH 10.0 CVE-2002-0665EPSS 11% Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL. Jrun Mitigation only Fix from $1,9502002-07-11 HIGH 10.0 CVE-2001-1514 ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security cont… Coldfusion Mitigation only Fix from $1,9502001-12-31 MEDIUM 5.0 CVE-2001-1510 Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote atta… Jrun No fix yet Fix from $1,6002001-12-31 HIGH 7.5 CVE-2001-0535 Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allow… Coldfusion Server Mitigation only Fix from $1,9502001-10-30 MEDIUM 5.0 CVE-2000-1052 Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet. Jrun Mitigation only Fix from $1,6002000-12-11 MEDIUM 5.0 CVE-1999-1526 Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia. Shockwave Flash Plugin Mitigation only Fix from $1,6001999-03-11