Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Shockwave HIGH 7.5
CVE-2007-1403EPSS 29%

Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial o…

No fix yet
Fix from $1,950 2007-03-10
Flash Player MEDIUM 5.0
CVE-2006-6827

Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.A…

No fix yet
Fix from $1,600 2006-12-31
Coldfusion MEDIUM 5.8
CVE-2006-2364

Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary…

No fix yet
Fix from $1,600 2006-05-15
Flash Media Server HIGH 7.8
CVE-2005-4216

The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (applicatio…

No fix yet
Fix from $1,950 2005-12-14
Coldfusion Fusebox MEDIUM 5.0
CVE-2005-2481

ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server pat…

Mitigation only
Fix from $1,600 2005-08-05
Jrun HIGH 7.5
CVE-2004-2182

Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information …

Mitigation only
Fix from $1,950 2004-12-31
Coldfusion HIGH 7.2
CVE-2004-2204

Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to c…

Mitigation only
Fix from $1,950 2004-12-31
Coldfusion MEDIUM 5.0
CVE-2003-1469EPSS 6%

The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the…

No fix yet
Fix from $1,600 2003-12-31
Flash Player MEDIUM 5.0
CVE-2002-1534

Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share.

No fix yet
Fix from $1,600 2003-03-31
Flash Player MEDIUM 5.0
CVE-2002-1881

Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a …

No fix yet
Fix from $1,600 2002-12-31
Flash Player HIGH 7.5
CVE-2002-1382

Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file …

Mitigation only
Fix from $1,950 2002-12-23
Sitespring HIGH 7.5
CVE-2002-1027

Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attacker…

No fix yet
Fix from $1,950 2002-10-04
Jrun MEDIUM 5.0
CVE-2002-0937EPSS 7%

The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that c…

No fix yet
Fix from $1,600 2002-10-04
Sitespring MEDIUM 5.0
CVE-2002-1026

Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long ma…

No fix yet
Fix from $1,600 2002-10-04
Shockwave Flash HIGH 7.5
CVE-2002-0846

The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than …

Mitigation only
Fix from $1,950 2002-08-12
Jrun HIGH 10.0
CVE-2002-0665EPSS 11%

Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.

Mitigation only
Fix from $1,950 2002-07-11
Coldfusion HIGH 10.0
CVE-2001-1514

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security cont…

Mitigation only
Fix from $1,950 2001-12-31
Jrun MEDIUM 5.0
CVE-2001-1510

Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote atta…

No fix yet
Fix from $1,600 2001-12-31
Coldfusion Server HIGH 7.5
CVE-2001-0535

Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allow…

Mitigation only
Fix from $1,950 2001-10-30
Jrun MEDIUM 5.0
CVE-2000-1052

Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.

Mitigation only
Fix from $1,600 2000-12-11
Shockwave Flash Plugin MEDIUM 5.0
CVE-1999-1526

Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.

Mitigation only
Fix from $1,600 1999-03-11