Skip to main content

Vendor/product archive

macromedia / jrun CVEs

Beta · best-effort

34 CVEs tagged to macromedia / jrun4 Critical, 6 High, 23 Medium, 1 Low, 0 Unrated.

CVE-2005-4472

Published Dec 22, 2005

Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4473

Published Dec 22, 2005

Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source code via "a malformed URL."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2306

Published Jul 19, 2005

Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could a…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1477

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the Management Console in JRun 4.0 allows remote attackers to execute arbitrary web script or HTML and possibly hijack a user's session.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2182

Published Dec 31, 2004

Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0646

Published Dec 23, 2004

Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1855

Published Dec 31, 2002

Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration inf…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2186

Published Dec 31, 2002

Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2187

Published Dec 31, 2002

Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1310

Published Nov 29, 2002

Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GE…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0937

Published Oct 4, 2002

The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(n…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1025

Published Oct 4, 2002

JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP file unparsed.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0801

Published Aug 12, 2002

Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header f…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-0665

Published Jul 11, 2002

Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1510

Published Dec 31, 2001

Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1511

Published Dec 31, 2001

JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source file…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1512

Published Dec 31, 2001

Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant o…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1513

Published Dec 31, 2001

Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application direct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1544

Published Dec 31, 2001

Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1545

Published Dec 31, 2001

Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session ID…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0926

Published Nov 28, 2001

SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a n…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 34 CVEsPage 1 of 2