Vulnerabilities > Macromedia > Jrun > High

DATE CVE VULNERABILITY TITLE RISK
2005-12-22 CVE-2005-4472 Multiple vulnerability in Macromedia JRun
Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request that is not properly handled during conversion to wide characters.
network
low complexity
macromedia
7.5
2004-12-31 CVE-2004-2182 Improper Authentication vulnerability in Macromedia Jrun 4.0/4.0Build61650
Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.
network
low complexity
macromedia CWE-287
7.5
2004-12-31 CVE-2004-1478 Remote vulnerability in Macromedia JRun
JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.
network
low complexity
hitachi macromedia
7.5
2002-11-29 CVE-2002-1310 Buffer Overrun vulnerability in Macromedia JRun IIS ISAPI Filter GET Request
Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name.
network
low complexity
macromedia
7.5
2001-12-31 CVE-2001-1513 Unspecified vulnerability in Macromedia Jrun 3.0/3.1
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.
network
low complexity
macromedia
7.5
2001-07-02 CVE-2001-1084 Cross-Site Scripting vulnerability in Macromedia Jrun 2.3.3/3.0
Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.
network
low complexity
macromedia
7.5