NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49141 | CVE-2009-1876 | Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a "double-encoded null character vulnerability." | 2 | 5 | Medium | 2017-01-07 | 2009-08-26 | View | |
42849 | CVE-2012-0770 | Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. | 2 | 5 | Medium | 2017-01-19 | 2012-03-14 | View | |
57930 | CVE-2007-5905 | Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
1598 | CVE-2008-1656 | Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these methods via Flex 2 remoting, a different vulnerability than CVE-2006-4725. | 2 | 7.5 | High | 2017-01-03 | 2012-10-29 | View | |
85428 | CVE-2017-3008 | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17016 of 17672, showing 5 records out of 88360 total, starting on record 85076, ending on 85080