<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>ColdFusion 8 Security Patches</title>
    <link>http://www.merlinmanager.com/</link>
    <description>ColdFusion 8 Security Patches</description>
    <language>en-us</language>

	
    <item>
      <title>APSB12-21 DOS Vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb12-21.html</link>
      <description><![CDATA[Adobe has released a security hotfix for ColdFusion 10 and earlier versions for Windows, Macintosh and UNIX. This update resolves a vulnerability which could result in a Denial of Service condition.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Wed, 12 Sep 2012 07:52:08 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb12-21.html</guid>
    </item>
	
    <item>
      <title>APSB12-15 HTTP response splitting vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb12-15.html</link>
      <description><![CDATA[Adobe released a security hotfix for ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. This update resolves an HTTP response splitting vulnerability in the ColdFusion Component Browser.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Fri, 15 Jun 2012 04:54:13 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb12-15.html</guid>
    </item>
	
    <item>
      <title>APSB11-29 Cross-Site Scripting Vulnerabilities</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb11-29.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to a cross-site scripting attack. Adobe has provided a solution to address the reported vulnerabilities. 

This update resolves a cross-site scripting vulnerability in cfform tag (CVE-2011-2463).

This update resolves a cross-site scripting vulnerability in RDS (CVE-2011-4368).]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Wed, 14 Dec 2011 01:17:28 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb11-29.html</guid>
    </item>
	
    <item>
      <title>APSB11-14 DOS and CSRF Security Patch</title>
      <link>http://kb2.adobe.com/cps/907/cpsid_90784.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to a cross-site request forgery (CSRF) or a remote denial-of-service (DoS).]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Thu, 16 Jun 2011 22:31:21 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/907/cpsid_90784.html</guid>
    </item>
	
    <item>
      <title>APSB11-04 XSS, Session Fixation, CRLF injection Vulnerabilities</title>
      <link>http://kb2.adobe.com/cps/890/cpsid_89094.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to cross-site scripting, Session Fixation, CRLF injection and information disclosure. Adobe recommends users update their product installation using the instructions provided below.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Wed, 09 Feb 2011 04:31:16 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/890/cpsid_89094.html</guid>
    </item>
	
    <item>
      <title>APSB10-18 Directory Traversal Vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb10-18.html</link>
      <description><![CDATA[An important vulnerability has been identified in ColdFusion 8.0, 8.0.1, 9.0, 9.0.1 for Windows, Macintosh and UNIX. This directory traversal vulnerability could lead to information disclosure (CVE-2010-2861). Adobe has provided a solution to the reported vulnerability. It is recommended that users update their product installation using the instructions provided above.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Wed, 11 Aug 2010 01:01:19 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb10-18.html</guid>
    </item>
	
    <item>
      <title>APSB10-11 ColdFusion cross-site scripting vulnerabilities</title>
      <link>http://kb2.adobe.com/cps/841/cpsid_84102.html</link>
      <description><![CDATA[Hotfix for cross-script scripting vulnerabilities in the CF Admin, componentutils and wizards login pages all in the CFIDE directory. This is a manual patch.\r\n\r\nA bug was found in this hotfix that affected CF8 64 bit installations and resolved by Adobe on May 13, 2010.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Thu, 13 May 2010 11:03:42 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/841/cpsid_84102.html</guid>
    </item>
	
    <item>
      <title>APSB10-05 Security update for Flash Remoting</title>
      <link>http://kb2.adobe.com/cps/822/cpsid_82241.html</link>
      <description><![CDATA[ColdFusion 9.0, 8.0.x and 7.0.2 are affected with the issue mentioned in the security bulletin APSB10-05 for BlazeDS. This technote provides fixes for the security issue along with the installation instructions.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Fri, 19 Feb 2010 05:00:40 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/822/cpsid_82241.html</guid>
    </item>
	
    <item>
      <title>APSB08-21 Update available for potential ColdFusion 8 privilege escalation issue</title>
      <link>http://www.adobe.com/support/security/bulletins/downloads/hf800-73122.jar</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb08-21.html\r\n\r\nA vulnerability in ColdFusion could allow a lower-privileged user to bypass sandbox security and access sensitive information, and could potentially lead to a privilege escalation attack. This issue is particularly applicable to ColdFusion servers in a shared hosting environment. This issue is not remotely exploitable.]]></description>
	  <category>Auto</category>
	  <category>8.0.0</category>
      <pubDate>Wed, 05 Nov 2008 20:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb08-21.html</guid>
    </item>
	
    <item>
      <title>APSB08-12 Update available for ColdFusion 8 CFC method access level issue</title>
      <link>http://www.adobe.com/support/coldfusion/ts/documents/kb403328/hf800-71471.zip</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb08-12.html\r\n\r\nCFC methods in ColdFusion 8 can be invoked from Flex 2 remoting even if the access level is set to �public�. A malicious user could be able to access functions not intended for remote use by the developer.]]></description>
	  <category>Manual</category>
	  <category>8.0.0</category>
      <pubDate>Wed, 09 Apr 2008 06:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb08-12.html</guid>
    </item>
	
    <item>
      <title>APSB09-12 Security Update: Hotfixes available for ColdFusion and JRun</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb09-12.html</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb09-12.html\r\n\r\nCritical vulnerabilities have been identified in ColdFusion v8.0.1 and earlier versions, and JRun 4.0. These vulnerabilities could lead to the potential compromise of user accounts or the affected system.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Mon, 17 Aug 2009 20:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb09-12.html</guid>
    </item>
	
    <item>
      <title>APSB09-09 Hotfix available for potential ColdFusion 8 input sanitization issue</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb09-09.html</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb09-09.html\r\n\r\nA vulnerability in FCKEditor, which is included as part of ColdFusion 8, could allow a remote attacker to upload files in arbitrary directories which could lead to a system compromise. This issue is remotely exploitable. There are reports that this issue is being exploited in the wild.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Wed, 08 Jul 2009 20:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb09-09.html</guid>
    </item>
	
    <item>
      <title>APSB08-21 Update available for potential ColdFusion 8 privilege escalation issue</title>
      <link>http://www.adobe.com/support/security/bulletins/downloads/hf801-73122.jar</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb08-21.html\r\n\r\nA vulnerability in ColdFusion could allow a lower-privileged user to bypass sandbox security and access sensitive information, and could potentially lead to a privilege escalation attack. This issue is particularly applicable to ColdFusion servers in a shared hosting environment. This issue is not remotely exploitable.]]></description>
	  <category>Auto</category>
	  <category>8.0.1</category>
      <pubDate>Wed, 05 Nov 2008 20:00:00 GMT</pubDate>
      <guid>http://adobe.com/support/security/bulletins/apsb08-21.html</guid>
    </item>
	
    <item>
      <title>APSB08-12 Update available for ColdFusion 8 CFC method access level issue</title>
      <link>http://www.adobe.com/support/coldfusion/ts/documents/kb403328/hf801-71471.zip</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb08-12.html\r\n\r\nCFC methods in ColdFusion 8 can be invoked from Flex 2 remoting even if the access level is set to �public�. A malicious user could be able to access functions not intended for remote use by the developer.]]></description>
	  <category>Manual</category>
	  <category>8.0.1</category>
      <pubDate>Tue, 08 Apr 2008 20:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb08-12.html</guid>
    </item>
	
    <item>
      <title>APSB08-06 Update available for potential ColdFusion MX 7 and ColdFusion 8 Cross Site Scripting security issue</title>
      <link>http://www.adobe.com/support/coldfusion/ts/documents/kb403070/chf8000003.zip</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb08-06.html\r\n\r\nContained in ColdFusion 8 Cumulative Hot Fix 3\r\n\r\nA potential vulnerability in ColdFusion MX7 and ColdFusion 8 could allow an attacker to execute cross-site scripting attack. This issue is specific to ColdFusion and Windows IIS 6 installations.]]></description>
	  <category>Auto</category>
	  <category>8.0.0</category>
      <pubDate>Tue, 11 Mar 2008 15:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb08-06.html</guid>
    </item>
	
    <item>
      <title>APSB08-07 Update available for ColdFusion MX 7 and ColdFusion 8 Cross-Site Scripting issue</title>
      <link>http://www.adobe.com/support/coldfusion/ts/documents/kb403070/chf8000003.zip</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb08-07.html\r\n\r\nContained in ColdFusion 8.0 Cumulative Hot Fix 3\r\n\r\nA vulnerability in ColdFusion 8 and ColdFusion MX 7 could allow an attacker to bypass ColdFusion�s cross-site scripting protection for certain ColdFusion applications. Only ColdFusion applications where the Application.cfm or Application.cfc contains the setEncoding function would be vulnerable to this attack.]]></description>
	  <category>Auto</category>
	  <category>8.0.0</category>
      <pubDate>Tue, 11 Mar 2008 20:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb08-07.html</guid>
    </item>
	
    <item>
      <title>APSB08-08 Update available for ColdFusion MX 7 and ColdFusion 8 logs invalid admin interface log-in attempts</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb08-08.html</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb08-08.html\r\n\r\nA design error in ColdFusion 8 and ColdFusion MX 7 could make it more likely that an attacker could attempt to log in to the admin interface undetected since failed log-in attempts were not previously logged.]]></description>
	  <category>Manual</category>
	  <category>8.0</category>
      <pubDate>Tue, 11 Mar 2008 20:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb08-08.html</guid>
    </item>
	
    <item>
      <title>APSB07-19 Update available for ColdFusion MX 7 and ColdFusion 8 potential session hijacking issue</title>
      <link>http://www.adobe.com/support/coldfusion/ts/documents/kb402805/hf800-70523.zip</link>
      <description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb07-19.html\r\n\r\nAn error in ColdFusion MX7 and ColdFusion 8 applications could allow an attacker to hijack user sessions. This issue does not apply to customers using J2EE session management.]]></description>
	  <category>Auto</category>
	  <category>8.0</category>
      <pubDate>Tue, 13 Nov 2007 20:00:00 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb07-19.html</guid>
    </item>
	

  </channel>
</rss>
