CVE Tools

Allaire

24 CVEs tracked since 2000. Since Feb 2000, none of them reached CISA KEV.

Allaire CVEs per month

Feb 2000 to Apr 2003. Point at a month, or focus the strip and use the arrow keys.
Allaire CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-0220
2000-03null or fewer
2000-0440
2000-05null or fewer
2000-06null or fewer
2000-0740
2000-08null or fewer
2000-09null or fewer
2000-1010
2000-11null or fewer
2000-12null or fewer
2001-0110
2001-0220
2001-03null or fewer
2001-04null or fewer
2001-0550
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-0920
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-0320
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-0410

Products

The products that kept showing up in Allaire's monthly top three, with their CVEs summed over those months.

  1. Coldfusion Server149 months
  2. Spectra43 months
  3. Forums33 months
  4. Clustercats11 month
  5. Coldfusion11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Allaire.

  1. CVE-2002-0576ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, w...5.0
  2. CVE-2002-0108Allaire Forums 2.0.4 and 2.0.5 and Forums! 3.0 and 3.1 allows remote authenticated users to spoof messages as other users by modifying the hidden form fields for the name and e-mail address.7.5
  3. CVE-2001-1120Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.6.4
  4. CVE-1999-0756ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.5.0
  5. CVE-1999-1124HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requ...7.5
  6. CVE-1999-0760Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.10.0
  7. CVE-1999-0922An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.5.0
  8. CVE-1999-0924The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.5.0
  9. CVE-1999-0800The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.5.0
  10. CVE-2000-0120The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.7.5
  11. CVE-1999-0757The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.2.1
  12. CVE-1999-0923Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.7.5
  13. CVE-2000-0862Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.6.4
  14. CVE-2000-0538ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.5.0
  15. CVE-2000-0297Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.6.4

The record

Peak rank
#3 in Feb 2001
Busiest month shown
May 2001, 5 CVEs
Months with a KEV entry
0 since Feb 2000
Monthly snapshots
10 since 2000
Allaire's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store