NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40658 | CVE-2013-5328 | Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors. | 2 | 7.8 | High | 2017-01-18 | 2013-11-13 | View | |
35926 | CVE-2014-9166 | Adobe ColdFusion 10 before Update 15 and 11 before Update 3 allows attackers to cause a denial of service (resource consumption) via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2014-12-11 | View | |
17575 | CVE-2016-1114 | Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
17576 | CVE-2016-1115 | Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2016-11-30 | View | |
85429 | CVE-2017-3066 | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 656 of 17672, showing 5 records out of 88360 total, starting on record 3276, ending on 3280