Vulnerabilities (CVE)

Filtered by vendor Adobe Subscribe
Filtered by product Coldfusion
Total 146 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-5860 1 Adobe 2 Coldfusion, Jrun 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2007-1874 1 Adobe 1 Coldfusion 2023-12-10 7.2 HIGH N/A
Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.
CVE-2006-6483 1 Adobe 1 Coldfusion 2023-12-10 2.6 LOW N/A
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.
CVE-2006-3978 1 Adobe 1 Coldfusion 2023-12-10 4.6 MEDIUM N/A
Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors.
CVE-2007-5905 1 Adobe 1 Coldfusion 2023-12-10 6.8 MEDIUM N/A
Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability.
CVE-2006-4724 1 Adobe 1 Coldfusion 2023-12-10 5.0 MEDIUM N/A
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.