5.9
CVE-2016-1115
- EPSS 2.49%
- Veröffentlicht 11.05.2016 01:59:44
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version 10.0 Update -
Adobe ≫ Coldfusion Version 10.0 Update update1
Adobe ≫ Coldfusion Version 10.0 Update update10
Adobe ≫ Coldfusion Version 10.0 Update update11
Adobe ≫ Coldfusion Version 10.0 Update update12
Adobe ≫ Coldfusion Version 10.0 Update update13
Adobe ≫ Coldfusion Version 10.0 Update update14
Adobe ≫ Coldfusion Version 10.0 Update update15
Adobe ≫ Coldfusion Version 10.0 Update update16
Adobe ≫ Coldfusion Version 10.0 Update update17
Adobe ≫ Coldfusion Version 10.0 Update update18
Adobe ≫ Coldfusion Version 10.0 Update update2
Adobe ≫ Coldfusion Version 10.0 Update update3
Adobe ≫ Coldfusion Version 10.0 Update update4
Adobe ≫ Coldfusion Version 10.0 Update update5
Adobe ≫ Coldfusion Version 10.0 Update update6
Adobe ≫ Coldfusion Version 10.0 Update update7
Adobe ≫ Coldfusion Version 10.0 Update update8
Adobe ≫ Coldfusion Version 10.0 Update update9
Adobe ≫ Coldfusion Version 11.0 Update -
Adobe ≫ Coldfusion Version 11.0 Update update1
Adobe ≫ Coldfusion Version 11.0 Update update2
Adobe ≫ Coldfusion Version 11.0 Update update3
Adobe ≫ Coldfusion Version 11.0 Update update4
Adobe ≫ Coldfusion Version 11.0 Update update5
Adobe ≫ Coldfusion Version 11.0 Update update6
Adobe ≫ Coldfusion Version 11.0 Update update7
Adobe ≫ Coldfusion Version 2016 Update -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.49% | 0.825 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.securitytracker.com/id/1035829
https://helpx.adobe.com/security/products/coldfusion/apsb16-16.html
http://www.securityfocus.com/bid/90514