NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69940 | CVE-2005-4342 | ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability." | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 72707 | CVE-2004-2330 | ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a large number of form fields. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72708 | CVE-2004-2331 | ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
| 68172 | CVE-2005-2481 | ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 76625 | CVE-2000-0382 | ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site. | 2 | 2.6 | Low | 2017-01-05 | 2008-09-10 | View |
Page 15053 of 17672, showing 5 records out of 88360 total, starting on record 75261, ending on 75265