Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2007-4758

Disclosure Date: September 08, 2007 (last updated October 04, 2023)
Multiple buffer overflows in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-4759

Disclosure Date: September 08, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-4760

Disclosure Date: September 08, 2007 (last updated October 04, 2023)
The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably the same issue as CVE-2007-3503.
0
Attacker Value
Unknown

CVE-2007-4563

Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2007-4564

Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2004-1478

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.
0
Attacker Value
Unknown

CVE-2004-0928

Disclosure Date: October 05, 2004 (last updated February 22, 2025)
The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm".
0