Vulnerabilities (CVE)

Filtered by vendor Macromedia Subscribe
Total 116 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1084 1 Macromedia 1 Jrun 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.
CVE-1999-1454 1 Macromedia 1 Matrix Screen Saver 2025-04-03 4.6 MEDIUM N/A
Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.
CVE-2002-1855 1 Macromedia 1 Jrun 2025-04-03 5.0 MEDIUM N/A
Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVE-2002-0801 1 Macromedia 1 Jrun 2025-04-03 10.0 HIGH N/A
Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a .jsp file.
CVE-2001-0179 1 Macromedia 1 Jrun 2025-04-03 5.0 MEDIUM N/A
Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."
CVE-2002-0477 1 Macromedia 1 Flash Player 2025-04-03 7.5 HIGH N/A
Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.
CVE-2005-4473 1 Macromedia 1 Jrun 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source code via "a malformed URL."
CVE-2004-2331 1 Macromedia 1 Coldfusion 2025-04-03 2.1 LOW 5.5 MEDIUM
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
CVE-2002-1534 1 Macromedia 1 Flash Player 2025-04-03 5.0 MEDIUM N/A
Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share.
CVE-2002-1467 1 Macromedia 2 Flash Player, Shockwave 2025-04-03 5.0 MEDIUM N/A
Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).
CVE-2000-1051 1 Macromedia 1 Jrun 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet.
CVE-2002-1382 1 Macromedia 1 Flash Player 2025-04-03 7.5 HIGH N/A
Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846.
CVE-2002-1309 1 Macromedia 1 Coldfusion 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary via an HTTP GET request with a long .cfm file name.
CVE-2004-2204 1 Macromedia 1 Coldfusion 2025-04-03 7.2 HIGH N/A
Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administrative passwords by creating CFML scripts that use CreateObject or CFOBJECT.
CVE-2005-4472 1 Macromedia 1 Jrun 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request that is not properly handled during conversion to wide characters.
CVE-2006-2364 1 Macromedia 1 Coldfusion 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary web script or HTML via a "_required" field when the associated normal field is missing or empty, which is not sanitized before being presented in an error message.