Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flash Player MEDIUM 5.0
CVE-2002-1881

Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a …

No fix yet
Fix from $1,600 2002-12-31
Coldfusion MEDIUM 5.0
CVE-2002-1992

Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long t…

Patch available
Fix from $1,600 2002-12-31
Jrun MEDIUM 5.0
CVE-2002-2186

Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL.

Patch available
Fix from $1,600 2002-12-31
Jrun MEDIUM 5.0
CVE-2002-2187

Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.

Patch available
Fix from $1,600 2002-12-31
Flash Player HIGH 7.5
CVE-2002-1382

Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file …

Mitigation only
Fix from $1,950 2002-12-23
Coldfusion HIGH 7.5
CVE-2002-1309

Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute …

Patch available
Fix from $1,950 2002-11-29
Jrun HIGH 7.5
CVE-2002-1310

Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to ex…

Fix: after 4.0
Fix from $1,950 2002-11-29
Sitespring HIGH 7.5
CVE-2002-1027

Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attacker…

No fix yet
Fix from $1,950 2002-10-04
Jrun MEDIUM 5.0
CVE-2002-0937EPSS 7%

The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that c…

No fix yet
Fix from $1,600 2002-10-04
Jrun MEDIUM 5.0
CVE-2002-1025

JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send…

Patch available
Fix from $1,600 2002-10-04
Sitespring MEDIUM 5.0
CVE-2002-1026

Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long ma…

No fix yet
Fix from $1,600 2002-10-04
Jrun HIGH 10.0
CVE-2002-0801EPSS 9%

Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter …

Patch available
Fix from $1,950 2002-08-12
Flash Player HIGH 7.5
CVE-2002-0477

Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FS…

Patch available
Fix from $1,950 2002-08-12
Shockwave Flash HIGH 7.5
CVE-2002-0846

The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than …

Mitigation only
Fix from $1,950 2002-08-12
Flash Player MEDIUM 5.0
CVE-2002-0476

Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save…

Patch available
Fix from $1,600 2002-08-12
Jrun HIGH 10.0
CVE-2002-0665EPSS 11%

Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.

Mitigation only
Fix from $1,950 2002-07-11
Flash Player HIGH 7.5
CVE-2002-0605

Buffer overflow in Flash OCX for Macromedia Flash 6 revision 23 (6,0,23,0) allows remote attackers to execute arbitrary code via a long movie paramet…

Patch available
Fix from $1,950 2002-06-18
Coldfusion HIGH 10.0
CVE-2001-1514

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security cont…

Mitigation only
Fix from $1,950 2001-12-31
Jrun HIGH 7.5
CVE-2001-1513

Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request …

Patch available
Fix from $1,950 2001-12-31
Jrun MEDIUM 6.4
CVE-2001-1512

Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaS…

Patch available
Fix from $1,600 2001-12-31
Jrun MEDIUM 5.0
CVE-2001-1510

Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote atta…

No fix yet
Fix from $1,600 2001-12-31
Jrun MEDIUM 5.0
CVE-2001-1511

JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request …

Patch available
Fix from $1,600 2001-12-31
Jrun MEDIUM 5.0
CVE-2001-1544

Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (do…

Patch available
Fix from $1,600 2001-12-31
Jrun MEDIUM 5.0
CVE-2001-1545

Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote …

Patch available
Fix from $1,600 2001-12-31
Jrun MEDIUM 5.0
CVE-2001-0926

SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web ro…

Patch available
Fix from $1,600 2001-11-28
Coldfusion Server HIGH 7.5
CVE-2001-0535

Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allow…

Mitigation only
Fix from $1,950 2001-10-30
Coldfusion HIGH 7.5
CVE-2001-1427

Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown atta…

Patch available
Fix from $1,950 2001-07-11
Jrun HIGH 7.5
CVE-2001-1084

Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .j…

Patch available
Fix from $1,950 2001-07-02
Jrun MEDIUM 5.0
CVE-2001-0179

Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed UR…

Patch available
Fix from $1,600 2001-05-03
Shockwave Flash Plugin HIGH 7.6
CVE-2001-0166

Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a…

Fix: after 8.0
Fix from $1,950 2001-03-26