Show filters
36 Total Results
Displaying 31-36 of 36
Sort by:
Attacker Value
Unknown

CVE-2005-4343

Disclosure Date: December 19, 2005 (last updated February 22, 2025)
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".
0
Attacker Value
Unknown

CVE-2005-4342

Disclosure Date: December 19, 2005 (last updated February 22, 2025)
ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability."
0
Attacker Value
Unknown

CVE-2005-4344

Disclosure Date: December 19, 2005 (last updated February 22, 2025)
Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an object despite the specified configuration.
0
Attacker Value
Unknown

CVE-2005-2306

Disclosure Date: July 19, 2005 (last updated February 22, 2025)
Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users.
0
Attacker Value
Unknown

CVE-2005-1555

Disclosure Date: May 10, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.
0
Attacker Value
Unknown

CVE-2004-1815

Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).
0