Search: "macromedia"

59 CVEs found

CVE-1999-1525
5.1 MEDIUM

Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.

Published: 1997-03-14
Products: 1
Vendors:
macromedia

Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

Published: 1998-06-11
Products: 1
Vendors:
macromedia
CVE-1999-1526
5.0 MEDIUM

Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.

Published: 1999-03-11
Products: 1
Vendors:
macromedia
CVE-1999-1454
4.6 MEDIUM

Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (...

Published: 1999-10-04
Products: 1
Vendors:
macromedia

Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.

Published: 2001-03-12
Products: 1
Vendors:
oliver_debon

Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.

Published: 2001-03-26
Products: 1
Vendors:
macromedia

Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trail...

Published: 2001-12-31
Products: 2
Vendors:
macromedia
CVE-2001-1544
5.0 MEDIUM

Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.

Published: 2001-12-31
Products: 3
Vendors:
macromedia
CVE-2001-1545
5.0 MEDIUM

Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions...

Published: 2001-12-31
Products: 2
Vendors:
macromedia

Buffer overflow in Flash OCX for Macromedia Flash 6 revision 23 (6,0,23,0) allows remote attackers to execute arbitrary code via a long movie parameter.

Published: 2002-06-18
Products: 1
Vendors:
macromedia
CVE-2002-0665
10.0 HIGH

Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.

Published: 2002-07-11
Products: 3
Vendors:
macromedia
CVE-2002-0476
5.0 MEDIUM

Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.

Published: 2002-08-12
Products: 1
Vendors:
macromedia

Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.

Published: 2002-08-12
Products: 1
Vendors:
macromedia
CVE-2002-0801
10.0 HIGH

Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a ....

Published: 2002-08-12
Products: 2
Vendors:
macromedia

The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length.

Published: 2002-08-12
Products: 1
Vendors:
macromedia
CVE-2002-1026
5.0 MEDIUM

Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long malformed request to TCP port 2500, possibly triggeri...

Published: 2002-10-04
Products: 1
Vendors:
macromedia

Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500...

Published: 2002-10-04
Products: 1
Vendors:
macromedia

Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary via an HTTP GET request with a long .cfm ...

Published: 2002-11-29
Products: 1
Vendors:
macromedia

Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long...

Published: 2002-11-29
Products: 1
Vendors:
macromedia

Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002...

Published: 2002-12-23
Products: 7
Vendors:
macromedia