← Back

Macromedia

macromedia

112 CVEs • 21 products

Products (21)

Click to collapse
Toggle

CVEs (112)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Macromedia
1Jrun
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP file unparsed.
1Macromedia
1Jrun
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).
1Macromedia
1Shockwave Flash
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length.
1Macromedia
1Jrun
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a .jsp file.
1Macromedia
1Flash Player
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.
1Macromedia
1Flash Player
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.
1Macromedia
1Jrun
Apr 16, 2026
Jul 11, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.
1Macromedia
1Flash Player
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Flash OCX for Macromedia Flash 6 revision 23 (6,0,23,0) allows remote attackers to execute arbitrary code via a long movie parameter.
1Macromedia
1Jrun
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer f...Show more
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.Show less
1Macromedia
1Jrun
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.
1Macromedia
1Coldfusion
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child proce...Show more
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.Show less
1Macromedia
1Jrun
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as...Show more
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.Show less
1Macromedia
1Jrun
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.
1Macromedia
1Jrun
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%25...Show more
JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".Show less
1Macromedia
1Jrun
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp...Show more
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.Show less
1Macromedia
1Jrun
Apr 16, 2026
Nov 28, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the reques...Show more
SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement.Show less
1Macromedia
1Coldfusion Server
Apr 16, 2026
Oct 30, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofin...Show more
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.Show less
1Macromedia
1Coldfusion
Apr 16, 2026
Jul 11, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors.
1Macromedia
1Jrun
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javas...Show more
Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.Show less
1Macromedia
1Jrun
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."