macromedia records
116 published records for vendor macromedia.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 47
- With a fix record
- 16.4%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer21
- CWE-189 Numeric Errors3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-399 Resource Management Errors2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
116 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2010-3654Weaponized | Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authpadobe · flash player · CWE-119 | Critical9.3 | — | 69.7% | Oct 29, 2010 |
43Plan | CVE-2002-0665Proof of concept | Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.macromedia · jrun | Critical10.0 | — | 10.7% | Jul 11, 2002 |
43Plan | CVE-2000-1053Proof of concept | Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack anmacromedia · jrun | Critical10.0 | — | 10.6% | Dec 11, 2000 |
43Plan | CVE-2002-0801No exploit | Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to thmacromedia · jrun | Critical10.0 | — | 9.1% | Aug 12, 2002 |
42Plan | CVE-2004-0646No exploit | Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apachmacromedia · coldfusion | Critical10.0 | — | 7.1% | Dec 23, 2004 |
40Plan | CVE-2009-3793No exploit | Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackadobe · flash player · CWE-399 | Critical9.3 | — | 9.4% | Jun 15, 2010 |
40Plan | CVE-2010-2167No exploit | Multiple heap-based buffer overflows in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, miadobe · flash player · CWE-119 | Critical9.3 | — | 9.0% | Jun 15, 2010 |
40Plan | CVE-2010-2185No exploit | Buffer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers tadobe · flash player · CWE-119 | Critical9.3 | — | 8.7% | Jun 15, 2010 |
40Plan | CVE-2001-1514No exploit | ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass secumacromedia · coldfusion | Critical10.0 | — | 1.4% | Dec 31, 2001 |
39Monitor | CVE-2007-1403Proof of concept | Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause amacromedia · shockwave | High7.5 | — | 29.2% | Mar 10, 2007 |
39Monitor | CVE-2010-2164No exploit | Use-after-free vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might alloadobe · flash player · CWE-399 | Critical9.3 | — | 7.4% | Jun 15, 2010 |
39Monitor | CVE-2010-2173No exploit | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitraryadobe · flash player · CWE-119 | Critical9.3 | — | 7.4% | Jun 15, 2010 |
39Monitor | CVE-2010-2170No exploit | Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers adobe · flash player · CWE-189 | Critical9.3 | — | 7.4% | Jun 15, 2010 |
39Monitor | CVE-2010-2174No exploit | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitraryadobe · flash player · CWE-119 | Critical9.3 | — | 7.4% | Jun 15, 2010 |
39Monitor | CVE-2010-2181No exploit | Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers adobe · flash player · CWE-189 | Critical9.3 | — | 7.4% | Jun 15, 2010 |
39Monitor | CVE-2010-2183No exploit | Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers adobe · flash player · CWE-189 | Critical9.3 | — | 7.4% | Jun 15, 2010 |
39Monitor | CVE-2010-2161No exploit | Array index error in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackersadobe · flash player · CWE-94 | Critical9.3 | — | 7.1% | Jun 15, 2010 |
39Monitor | CVE-2010-2163No exploit | Multiple unspecified vulnerabilities in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, miadobe · flash player · CWE-94 | Critical9.3 | — | 7.1% | Jun 15, 2010 |
39Monitor | CVE-2010-2188No exploit | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of servadobe · flash player · CWE-119 | Critical9.3 | — | 6.8% | Jun 15, 2010 |
39Monitor | CVE-2010-2160No exploit | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of servadobe · flash player · CWE-119 | Critical9.3 | — | 6.8% | Jun 15, 2010 |
39Monitor | CVE-2010-2162No exploit | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of servadobe · flash player · CWE-119 | Critical9.3 | — | 6.8% | Jun 15, 2010 |
39Monitor | CVE-2010-2171No exploit | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of servadobe · flash player · CWE-119 | Critical9.3 | — | 6.8% | Jun 15, 2010 |
39Monitor | CVE-2010-2186No exploit | Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackadobe · flash player · CWE-94 | Critical9.3 | — | 6.7% | Jun 15, 2010 |
39Monitor | CVE-2010-2165No exploit | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of servadobe · flash player · CWE-119 | Critical9.3 | — | 6.1% | Jun 15, 2010 |
39Monitor | CVE-2010-2178No exploit | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of servadobe · flash player · CWE-119 | Critical9.3 | — | 6.1% | Jun 15, 2010 |
- CVE-2010-365458Plan
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authp
CriticalCVSS 9.3WeaponizedEPSS 70%adobe · flash playerOct 29, 2010
- CVE-2002-066543Plan
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.
CriticalCVSS 10.0Proof of conceptEPSS 11%macromedia · jrunJul 11, 2002
- CVE-2000-105343Plan
Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack an
CriticalCVSS 10.0Proof of conceptEPSS 11%macromedia · jrunDec 11, 2000
- CVE-2002-080143Plan
Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to th
CriticalCVSS 10.0No exploitEPSS 9%macromedia · jrunAug 12, 2002
- CVE-2004-064642Plan
Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apach
CriticalCVSS 10.0No exploitEPSS 7%macromedia · coldfusionDec 23, 2004
- CVE-2009-379340Plan
Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attack
CriticalCVSS 9.3No exploitEPSS 9%adobe · flash playerJun 15, 2010
- CVE-2010-216740Plan
Multiple heap-based buffer overflows in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, mi
CriticalCVSS 9.3No exploitEPSS 9%adobe · flash playerJun 15, 2010
- CVE-2010-218540Plan
Buffer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers t
CriticalCVSS 9.3No exploitEPSS 9%adobe · flash playerJun 15, 2010
- CVE-2001-151440Plan
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass secu
CriticalCVSS 10.0No exploitEPSS 1%macromedia · coldfusionDec 31, 2001
- CVE-2007-140339Monitor
Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a
HighCVSS 7.5Proof of conceptEPSS 29%macromedia · shockwaveMar 10, 2007
- CVE-2010-216439Monitor
Use-after-free vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allo
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-217339Monitor
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-217039Monitor
Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-217439Monitor
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-218139Monitor
Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-218339Monitor
Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-216139Monitor
Array index error in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-216339Monitor
Multiple unspecified vulnerabilities in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, mi
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-218839Monitor
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-216039Monitor
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-216239Monitor
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-217139Monitor
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-218639Monitor
Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attack
CriticalCVSS 9.3No exploitEPSS 7%adobe · flash playerJun 15, 2010
- CVE-2010-216539Monitor
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 6%adobe · flash playerJun 15, 2010
- CVE-2010-217839Monitor
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 6%adobe · flash playerJun 15, 2010