CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
737 | CVE-1999-0757 | Candidate | The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates. | Proposed (20010214) | ACCEPT(3) Baker, Cole, Frech | NOOP(1) Christey | Frech> XF:coldfusion-encryption | Christey> BUGTRAQ:19990724 Re: New Allaire Security Zone Bulletins and KB Articles | URL:http://www.securityfocus.com/archive/1/19471 | Christey> ADDREF BID:275 | URL:http://www.securityfocus.com/bid/275 | View |
903 | CVE-1999-0923 | Candidate | Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls. | Proposed (20010214) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:coldfusion-source-display(1741) | XF:coldfusion-syntax-checker(1742) | XF:coldfusion-file-existence(1743) | XF:coldfusion-sourcewindow(1744) | Christey> List all affected runnable code snippets to facilitate | search, which may include: | viewexample.cfm (though could that be part of CVE-1999-0922?) | View |
3349 | CVE-2001-0535 | Candidate | Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host"s domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script. | Proposed (20011012) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(2) Foat, Frech | NOOP(1) Christey | REVIEWING(1) Wall | Frech> XF:coldfusion-webpublish-execute-code(6790) | XF:coldfusion-email-view-files(6791) | Foat> Includes ColdFusion Server 4.x and earlier | Christey> Consider adding BID:3154 | View |
3031 | CVE-2001-0210 | Candidate | Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter. | Proposed (20010309) | MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese | Frech> XF:commerce-cgi-view-files(6095) | View |
3646 | CVE-2001-0840 | Candidate | Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI. | Modified (20050703) | ACCEPT(4) Armstrong, Baker, Bishop, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:compaq-insightmanager-xe-bo(7411) | View |
Page 20754 of 20943, showing 5 records out of 104715 total, starting on record 103766, ending on 103770