Page 14 of 116 results (0.005 seconds)

CVSS: 5.0EPSS: 28%CPEs: 12EXPL: 0

Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption). • http://marc.info/?l=bugtraq&m=107936690702515&w=2 http://secunia.com/advisories/11132 http://www.macromedia.com/devnet/security/security_zone/mpsb04-04.html http://www.securityfocus.com/bid/9877 https://exchange.xforce.ibmcloud.com/vulnerabilities/15473 •

CVSS: 5.0EPSS: 1%CPEs: 12EXPL: 0

Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption). • http://marc.info/?l=bugtraq&m=107936690702515&w=2 http://secunia.com/advisories/11130 http://sunsolve.sun.com/search/document.do?assetkey=1-26-57517-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-201713-1 http://www.securityfocus.com/bid/9877 https://exchange.xforce.ibmcloud.com/vulnerabilities/15473 •

CVSS: 5.0EPSS: 2%CPEs: 7EXPL: 2

The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message. • https://www.exploit-db.com/exploits/22544 http://securityreason.com/securityalert/3307 http://www.nii.co.in/vuln/pdmac.html http://www.securityfocus.com/archive/1/319867 http://www.securityfocus.com/bid/7443 https://exchange.xforce.ibmcloud.com/vulnerabilities/11879 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.0EPSS: 0%CPEs: 10EXPL: 2

Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explorer and Opera, which allows remote attackers to read restricted files via vulnerabilities in web browsers whose exploits rely on predictable names. El Reproductor de Macromedia Flash en versiones anteriores a 7,0,19,0 almacena un fichero de datos de Flash en una localización predecible, accesible a navegadores web como Internet Explorer y Opera, lo que permite a a atacantes remotos leer ficheros restringidos mediante vulnerabilidades en navegadores web cuya explotación se basa en nombres predecibles. • https://www.exploit-db.com/exploits/23298 http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html http://www.securityfocus.com/bid/8900 https://exchange.xforce.ibmcloud.com/vulnerabilities/14013 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field. Vulnerabilidad de scripting cruza-sitios (XSS) en la capacidad de seguimiento de publicidad de usuario Macromedia Flash permite a atacantes remotos insertar Javascript arbitrario mediante el campo clickTAG. • http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004514.html http://marc.info/?l=bugtraq&m=105033712615013&w=2 http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm http://www.securiteam.com/securitynews/5XP0B0U9PE.html •