NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65028 | CVE-2006-6483 | Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
65027 | CVE-2006-6482 | Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server"s internal IP address in an HREF tag. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
17297 | CVE-2016-0949 | Adobe Connect before 9.5.2 allows remote attackers to have an unspecified impact via a crafted parameter in a URL. | 2 | 10 | High | 2017-01-19 | 2016-12-05 | View | |
17298 | CVE-2016-0950 | Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View | |
21903 | CVE-2016-7851 | Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in cross-site scripting attacks. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 660 of 17672, showing 5 records out of 88360 total, starting on record 3296, ending on 3300