NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 76625 | CVE-2000-0382 | ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site. | 2 | 2.6 | Low | 2017-01-05 | 2008-09-10 | View | |
| 68172 | CVE-2005-2481 | ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 72708 | CVE-2004-2331 | ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
| 72707 | CVE-2004-2330 | ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a large number of form fields. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 69940 | CVE-2005-4342 | ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability." | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View |
Page 2620 of 17672, showing 5 records out of 88360 total, starting on record 13096, ending on 13100