Vulnerabilities > Adobe

DATE CVE VULNERABILITY TITLE RISK
2006-09-14 CVE-2006-4726 Cross-Site Scripting vulnerability in Adobe ColdFusion Error Page
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
network
high complexity
adobe
2.6
2006-09-14 CVE-2006-4725 Unspecified vulnerability in Adobe Coldfusion 7.0/7.0.1
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
local
low complexity
adobe
4.6
2006-09-14 CVE-2006-4724 Denial of Service vulnerability in Adobe ColdFusion Flash Remoting Gateway
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.
network
low complexity
adobe
5.0
2006-09-12 CVE-2006-4640 Permissions, Privileges, and Access Controls vulnerability in Adobe Flash Player
Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attackers to bypass the allowScriptAccess protection via unspecified vectors.
network
adobe CWE-264
6.8
2006-09-12 CVE-2006-3311 Remote Code Execution vulnerability in Adobe Flash Player
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.
network
high complexity
adobe
5.1
2006-08-03 CVE-2006-3459 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Libtiff
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c.
network
low complexity
libtiff adobe CWE-119
7.5
2006-07-13 CVE-2006-3588 Multiple vulnerability in Adobe Flash Player 8.0.24.0
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to cause a denial of service (browser crash) via a malformed, compressed .swf file, a different issue than CVE-2006-3587.
network
high complexity
adobe
2.6
2006-07-13 CVE-2006-3587 Multiple vulnerability in Adobe Flash Player 8.0.24.0
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
network
high complexity
adobe
5.1
2006-07-13 CVE-2006-3453 Remote Buffer Overflow vulnerability in Adobe Acrobat
Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via unknown vectors in a document that triggers the overflow when it is distilled to PDF.
network
high complexity
adobe
5.1
2006-07-12 CVE-2006-3452 Local Privilege Escalation vulnerability in Adobe Acrobat / Adobe Reader
Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files.
local
low complexity
adobe
4.6