Adobe

Coldfusion

201 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.44%
  • Veröffentlicht 14.10.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:11:32

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does ...

  • EPSS 21.23%
  • Veröffentlicht 14.10.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:11:32

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does ...

  • EPSS 4.89%
  • Veröffentlicht 14.10.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:16:26

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context ...

  • EPSS 2.75%
  • Veröffentlicht 14.10.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:16:26

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue do...

  • EPSS 0.96%
  • Veröffentlicht 14.10.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:16:26

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploita...

  • EPSS 15.88%
  • Veröffentlicht 14.10.2022 20:15:11
  • Zuletzt bearbeitet 21.11.2024 07:11:29

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does...

  • EPSS 0.5%
  • Veröffentlicht 12.05.2022 19:15:49
  • Zuletzt bearbeitet 21.11.2024 06:57:59

ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may ...

  • EPSS 0.07%
  • Veröffentlicht 27.05.2021 21:15:19
  • Zuletzt bearbeitet 21.11.2024 04:54:54

The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-e...

  • EPSS 81.79%
  • Veröffentlicht 15.04.2021 14:15:16
  • Zuletzt bearbeitet 21.11.2024 05:47:32

Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse th...

  • EPSS 0.15%
  • Veröffentlicht 17.07.2020 00:15:11
  • Zuletzt bearbeitet 05.05.2025 17:16:04

Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.