Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
macromedia vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2001-1084
Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.
Macromedia Jrun 3.0
Macromedia Jrun 2.3.3
641
VMScore
CVE-2004-2335
The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studio, install the AuthenticationService setuid and writable by other users, which allows local users to gain privileges by modifying t...
Macromedia Contribute 2.0
Macromedia Studio 2004
668
VMScore
CVE-2005-4472
Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a long request that is not properly handled during conversion to wide characters.
Macromedia Jrun 4.0
Macromedia Jrun 4.0 Build 61650
445
VMScore
CVE-2005-4473
Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote malicious users to view web application source code via "a malformed URL."
Macromedia Jrun 4.0
Macromedia Jrun 4.0 Build 61650
505
VMScore
CVE-2004-2505
Macromedia ColdFusion MX prior to 6.1 does not restrict the size of error messages, which allows remote malicious users to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.
Macromedia Coldfusion 5.0
Macromedia Coldfusion 6.0
1 EDB exploit
641
VMScore
CVE-2006-3979
The AdminAPI of ColdFusion MX 7 allows malicious users to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Administrator.
Macromedia Coldfusion 7.0
Macromedia Coldfusion 7.02
445
VMScore
CVE-2001-1511
JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote malicious users to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".
Macromedia Jrun 3.0
Macromedia Jrun 3.1
668
VMScore
CVE-2001-1513
Macromedia JRun 3.0 and 3.1 allows remote malicious users to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.
Macromedia Jrun 3.0
Macromedia Jrun 3.1
890
VMScore
CVE-2001-1514
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function an...
Macromedia Coldfusion 5.0
Macromedia Coldfusion 4.5
445
VMScore
CVE-2001-1545
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote malicious users to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.
Macromedia Jrun 3.0
Macromedia Jrun 3.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4651
CVE-2024-34255
elevation of privilege
CVE-2024-25529
CVE-2024-4671
NULL pointer dereference
CVE-2024-25527
template injection
CVE-2008-0166
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »