Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Shockwave HIGH 7.5
CVE-2007-1403EPSS 29%

Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial o…

No fix yet
Fix from $1,950 2007-03-10
Flash Player MEDIUM 5.0
CVE-2006-6827

Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.A…

No fix yet
Fix from $1,600 2006-12-31
Coldfusion HIGH 7.2
CVE-2006-3979

The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Ad…

Patch available
Fix from $1,950 2006-08-09
Coldfusion MEDIUM 5.8
CVE-2006-2364

Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary…

No fix yet
Fix from $1,600 2006-05-15
Flash Player MEDIUM 5.1
CVE-2006-0024EPSS 7%

Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF fi…

Fix: after 8.0.22.0
Fix from $1,600 2006-03-15
Jrun HIGH 7.5
CVE-2005-4472

Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbit…

Patch available
Fix from $1,950 2005-12-22
Jrun MEDIUM 5.0
CVE-2005-4473

Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source code via "a malformed URL."

Patch available
Fix from $1,600 2005-12-22
Coldfusion HIGH 7.5
CVE-2005-4342

ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager i…

Patch available
Fix from $1,950 2005-12-19
Coldfusion HIGH 7.2
CVE-2005-4345

Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain …

Patch available
Fix from $1,950 2005-12-19
Coldfusion MEDIUM 5.0
CVE-2005-4343

Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a craf…

Patch available
Fix from $1,600 2005-12-19
Flash Media Server HIGH 7.8
CVE-2005-4216

The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (applicatio…

No fix yet
Fix from $1,950 2005-12-14
Flash Communication Server HIGH 7.8
CVE-2005-3901

Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of se…

Patch available
Fix from $1,950 2005-11-29
Flash Player HIGH 7.5
CVE-2005-3591EPSS 10%

Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to caus…

Patch available
Fix from $1,950 2005-11-16
Flash Player MEDIUM 5.1
CVE-2005-2628EPSS 7%

Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is u…

Patch available
Fix from $1,600 2005-11-05
Coldfusion Fusebox MEDIUM 5.0
CVE-2005-2481

ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server pat…

Mitigation only
Fix from $1,600 2005-08-05
Coldfusion MEDIUM 5.0
CVE-2005-1022

ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sen…

Patch available
Fix from $1,600 2005-05-02
Jrun HIGH 7.5
CVE-2004-2182

Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information …

Mitigation only
Fix from $1,950 2004-12-31
Coldfusion HIGH 7.2
CVE-2004-2204

Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to c…

Mitigation only
Fix from $1,950 2004-12-31
Contribute HIGH 7.2
CVE-2004-2335

The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studi…

Patch available
Fix from $1,950 2004-12-31
Coldfusion MEDIUM 5.5
CVE-2004-2331

ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection m…

Patch available
Fix from $1,600 2004-12-31
Coldfusion MEDIUM 5.0
CVE-2004-2330

ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a large number of form fields.

Patch available
Fix from $1,600 2004-12-31
Coldfusion MEDIUM 5.0
CVE-2004-2505

Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory …

Patch available
Fix from $1,600 2004-12-31
Coldfusion HIGH 10.0
CVE-2004-0646EPSS 7%

Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with v…

Patch available
Fix from $1,950 2004-12-23
Coldfusion MEDIUM 5.0
CVE-2004-1815

Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote a…

Patch available
Fix from $1,600 2004-03-15
Director MEDIUM 5.0
CVE-2003-1017

Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explor…

Patch available
Fix from $1,600 2004-01-05
Coldfusion MEDIUM 5.0
CVE-2003-1469EPSS 6%

The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the…

No fix yet
Fix from $1,600 2003-12-31
Flash Player MEDIUM 5.0
CVE-2002-1467

Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redire…

Patch available
Fix from $1,600 2003-04-22
Flash Player MEDIUM 5.0
CVE-2002-1534

Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share.

No fix yet
Fix from $1,600 2003-03-31
Flash Player MEDIUM 5.0
CVE-2002-1625

Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of servic…

Patch available
Fix from $1,600 2002-12-31
Jrun MEDIUM 5.0
CVE-2002-1855

Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java cla…

Patch available
Fix from $1,600 2002-12-31