Vulnerabilities > Macromedia > Jrun > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-12-22 | CVE-2005-4472 | Multiple vulnerability in Macromedia JRun Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request that is not properly handled during conversion to wide characters. | 7.5 |
2004-12-31 | CVE-2004-2182 | Improper Authentication vulnerability in Macromedia Jrun 4.0/4.0Build61650 Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server. | 7.5 |
2004-12-31 | CVE-2004-1478 | Remote vulnerability in Macromedia JRun JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session. | 7.5 |
2002-11-29 | CVE-2002-1310 | Buffer Overrun vulnerability in Macromedia JRun IIS ISAPI Filter GET Request Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name. | 7.5 |
2001-12-31 | CVE-2001-1513 | Unspecified vulnerability in Macromedia Jrun 3.0/3.1 Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx. | 7.5 |
2001-07-02 | CVE-2001-1084 | Cross-Site Scripting vulnerability in Macromedia Jrun 2.3.3/3.0 Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message. | 7.5 |