Vulnerabilities > Adobe > High

DATE CVE VULNERABILITY TITLE RISK
2008-04-09 CVE-2008-1656 Permissions, Privileges, and Access Controls vulnerability in Adobe Coldfusion 8.0/8.1
Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these methods via Flex 2 remoting, a different vulnerability than CVE-2006-4725.
network
low complexity
adobe CWE-264
7.5
2008-03-12 CVE-2008-1203 Unspecified vulnerability in Adobe Coldfusion 7.0/8.0
The administrator interface for Adobe ColdFusion 8 and ColdFusion MX7 does not log failed authentication attempts, which makes it easier for remote attackers to conduct brute force attacks without detection.
network
low complexity
adobe
7.5
2007-05-18 CVE-2007-2682 Unspecified vulnerability in Adobe Creative Suite 3.0
The installer for Adobe Version Cue CS3 Server on Apple Mac OS X, as used in Adobe Creative Suite 3 (CS3), does not re-enable the personal firewall after completing the product installation, which allows remote attackers to bypass intended firewall rules.
network
low complexity
apple adobe
7.5
2007-04-11 CVE-2007-1874 Unspecified vulnerability in Adobe Coldfusion 7.0
Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.
local
low complexity
adobe
7.2
2007-04-11 CVE-2007-1279 Local Privilege Escalation vulnerability in Adobe Bridge 1.0.3
Unspecified vulnerability in the installer for Adobe Bridge 1.0.3 update for Apple OS X, when patching with desktop management tools, allows local users to gain privileges via unspecified vectors during installation of the update by a different user who has administrative privileges.
local
low complexity
apple adobe
7.2
2007-01-03 CVE-2007-0046 Remote Security vulnerability in Reader
Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
network
low complexity
adobe
7.5
2006-08-03 CVE-2006-3459 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Libtiff
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c.
network
low complexity
libtiff adobe CWE-119
7.5
2006-05-09 CVE-2006-2042 SQL Injection vulnerability in Adobe Dreamweaver Generated Code
Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that allows SQL injection attacks in the (1) ColdFusion, (2) PHP mySQL, (3) ASP, (4) ASP.NET, and (5) JSP server models.
network
low complexity
adobe
7.5
2006-04-13 CVE-2006-1627 Remote vulnerability in Adobe Document Server for Reader Extensions
Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters.
network
low complexity
adobe
7.5
2005-12-31 CVE-2005-4708 Local Privilege Escalation vulnerability in Macromedia eLicensing Client Activation Code
Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.
local
low complexity
adobe
7.2