|
246271
|
7.5 |
HIGH
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitatio…
|
CWE-200
Information Exposure
|
CVE-2018-15964
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246272
|
5.3 |
MEDIUM
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary fold…
|
NVD-CWE-noinfo
|
CVE-2018-15963
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246273
|
5.3 |
MEDIUM
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. Successful exploitation could lead to information …
|
CWE-200
Information Exposure
|
CVE-2018-15962
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246274
|
9.8 |
CRITICAL
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-15961
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246275
|
7.5 |
HIGH
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitatio…
|
CWE-20
Improper Input Validation
|
CVE-2018-15960
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246276
|
9.8 |
CRITICAL
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-15959
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246277
|
9.8 |
CRITICAL
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-15958
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246278
|
9.8 |
CRITICAL
Network
|
adobe
|
coldfusion
|
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-15957
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246279
|
4.4 |
MEDIUM
Local
|
avaya
|
call_management_system_supervisor
|
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected vers…
|
CWE-200
Information Exposure
|
CVE-2018-15615
|
2024-11-21 12:51 |
2018-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246280
|
6.1 |
MEDIUM
Network
|
avaya
|
aura_orchestration_designer
|
A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avay…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15613
|
2024-11-21 12:51 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|