NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 78945 | CVE-2001-1514 | ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account. | 2 | 10 | High | 2017-01-05 | 2008-09-05 | View | |
| 79581 | CVE-2002-0576 | ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 66771 | CVE-2005-1022 | ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 76780 | CVE-2000-0538 | ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
| 75406 | CVE-1999-0756 | ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 2619 of 17672, showing 5 records out of 88360 total, starting on record 13091, ending on 13095