Search: "macromedia"

59 CVEs found

CVE-2002-1625
5.0 MEDIUM

Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of service (bandwidth, resource, and CPU consumption) via th...

Published: 2002-12-31
Products: 1
Vendors:
macromedia
CVE-2002-1700
4.3 MEDIUM

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTT...

Published: 2002-12-31
Products: 3
Vendors:
macromedia microsoft
CVE-2002-1855
5.0 MEDIUM

Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a reque...

Published: 2002-12-31
Products: 3
Vendors:
macromedia
CVE-2002-1881
5.0 MEDIUM

Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ...

Published: 2002-12-31
Products: 7
Vendors:
macromedia
CVE-2002-2186
5.0 MEDIUM

Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL.

Published: 2002-12-31
Products: 3
Vendors:
macromedia
CVE-2002-2187
5.0 MEDIUM

Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.

Published: 2002-12-31
Products: 3
Vendors:
macromedia
CVE-2002-1534
5.0 MEDIUM

Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share.

Published: 2003-03-31
Products: 4
Vendors:
macromedia
CVE-2002-1467
5.0 MEDIUM

Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) ...

Published: 2003-04-22
Products: 4
Vendors:
macromedia
CVE-2003-0208
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.

Published: 2003-05-05
Products: 1
Vendors:
macromedia
CVE-2003-1017
5.0 MEDIUM

Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explorer and Opera, which allows remote attackers to read...

Published: 2004-01-05
Products: 10
Vendors:
macromedia
CVE-2004-0928
5.0 MEDIUM

The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, v...

Published: 2004-10-05
Products: 11
Vendors:
macromedia hitachi

Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.

Published: 2004-12-31
Products: 4
Vendors:
macromedia

Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administr...

Published: 2004-12-31
Products: 2
Vendors:
macromedia

The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studio, install the AuthenticationService setuid and wri...

Published: 2004-12-31
Products: 2
Vendors:
macromedia
CVE-2004-2505
5.0 MEDIUM

Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or P...

Published: 2004-12-31
Products: 2
Vendors:
macromedia

Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated us...

Published: 2005-07-19
Products: 3
Vendors:
macromedia

The "reset password" feature in Macromedia Breeze 5.0 stores passwords in plaintext in the database instead of the hash, which allows attackers with access to the database to obtain the passwords.

Published: 2005-09-30
Products: 1
Vendors:
macromedia
CVE-2005-2628
5.1 MEDIUM

Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function p...

Published: 2005-11-05
Products: 8
Vendors:
macromedia

Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute ...

Published: 2005-11-16
Products: 8
Vendors:
macromedia
CVE-2005-3800
5.0 MEDIUM

Macromedia Contribute Publishing Server (CPS) before 1.11 uses a weak algorithm to encrypt user password in connection keys that use shared FTP login credentials, which allows attackers to obtain sens...

Published: 2005-11-24
Products: 2
Vendors:
macromedia