Show filters
54 Total Results
Displaying 31-40 of 54
Sort by:
Attacker Value
Unknown
CVE-2020-3768
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2020-3796
Disclosure Date: June 26, 2020 (last updated November 28, 2024)
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an improper access control vulnerability. Successful exploitation could lead to system file structure disclosure.
0
Attacker Value
Unknown
CVE-2020-3767
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability. Successful exploitation could lead to application-level denial-of-service (dos).
0
Attacker Value
Unknown
CVE-2020-3761
Disclosure Date: March 25, 2020 (last updated November 27, 2024)
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a remote file read vulnerability. Successful exploitation could lead to arbitrary file read from the coldfusion install directory.
0
Attacker Value
Unknown
CVE-2020-3794
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
0
Attacker Value
Unknown
CVE-2019-8256
Disclosure Date: December 19, 2019 (last updated November 27, 2024)
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2019-8073
Disclosure Date: September 27, 2019 (last updated November 27, 2024)
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.
0
Attacker Value
Unknown
CVE-2019-8074
Disclosure Date: September 27, 2019 (last updated November 27, 2024)
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.
0
Attacker Value
Unknown
CVE-2019-8072
Disclosure Date: September 27, 2019 (last updated November 27, 2024)
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
0
Attacker Value
Unknown
CVE-2019-7840
Disclosure Date: June 12, 2019 (last updated November 27, 2024)
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
0