Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2007-1403EPSS 29% Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial o… Shockwave No fix yet Fix from $1,9502007-03-10 MEDIUM 5.0 CVE-2006-6827 Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.A… Flash Player No fix yet Fix from $1,6002006-12-31 HIGH 7.2 CVE-2006-3979 The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Ad… Coldfusion Patch available Fix from $1,9502006-08-09 MEDIUM 5.8 CVE-2006-2364 Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary… Coldfusion No fix yet Fix from $1,6002006-05-15 MEDIUM 5.1 CVE-2006-0024EPSS 7% Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF fi… Flash Player after 8.0.22.0 Fix from $1,6002006-03-15 HIGH 7.5 CVE-2005-4472 Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbit… Jrun Patch available Fix from $1,9502005-12-22 MEDIUM 5.0 CVE-2005-4473 Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source code via "a malformed URL." Jrun Patch available Fix from $1,6002005-12-22 HIGH 7.5 CVE-2005-4342 ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager i… Coldfusion Patch available Fix from $1,9502005-12-19 HIGH 7.2 CVE-2005-4345 Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain … Coldfusion Patch available Fix from $1,9502005-12-19 MEDIUM 5.0 CVE-2005-4343 Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a craf… Coldfusion Patch available Fix from $1,6002005-12-19 HIGH 7.8 CVE-2005-4216 The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (applicatio… Flash Media Server No fix yet Fix from $1,9502005-12-14 HIGH 7.8 CVE-2005-3901 Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of se… Flash Communication Server Patch available Fix from $1,9502005-11-29 HIGH 7.5 CVE-2005-3591EPSS 10% Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to caus… Flash Player Patch available Fix from $1,9502005-11-16 MEDIUM 5.1 CVE-2005-2628EPSS 7% Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is u… Flash Player Patch available Fix from $1,6002005-11-05 MEDIUM 5.0 CVE-2005-2481 ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server pat… Coldfusion Fusebox Mitigation only Fix from $1,6002005-08-05 MEDIUM 5.0 CVE-2005-1022 ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sen… Coldfusion Patch available Fix from $1,6002005-05-02 HIGH 7.5 CVE-2004-2182 Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information … Jrun Mitigation only Fix from $1,9502004-12-31 HIGH 7.2 CVE-2004-2204 Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to c… Coldfusion Mitigation only Fix from $1,9502004-12-31 HIGH 7.2 CVE-2004-2335 The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studi… Contribute Patch available Fix from $1,9502004-12-31 MEDIUM 5.5 CVE-2004-2331 ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection m… Coldfusion Patch available Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-2330 ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a large number of form fields. Coldfusion Patch available Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-2505 Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory … Coldfusion Patch available Fix from $1,6002004-12-31 HIGH 10.0 CVE-2004-0646EPSS 7% Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with v… Coldfusion Patch available Fix from $1,9502004-12-23 MEDIUM 5.0 CVE-2004-1815 Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote a… Coldfusion Patch available Fix from $1,6002004-03-15 MEDIUM 5.0 CVE-2003-1017 Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explor… Director Patch available Fix from $1,6002004-01-05 MEDIUM 5.0 CVE-2003-1469EPSS 6% The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the… Coldfusion No fix yet Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2002-1467 Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redire… Flash Player Patch available Fix from $1,6002003-04-22 MEDIUM 5.0 CVE-2002-1534 Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share. Flash Player No fix yet Fix from $1,6002003-03-31 MEDIUM 5.0 CVE-2002-1625 Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of servic… Flash Player Patch available Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1855 Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java cla… Jrun Patch available Fix from $1,6002002-12-31