CVE-2009-3960Medium· 6.5▾ Midnight⚠ Exploited in the wildPoC availableUnspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 35.8 · likelihood 18 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 7, 2022
Last analysed / modified upstream
90%
Exploit-DB · Metasploit ×1 (last check)
Added to the CISA catalog on Mar 7, 2022. Federal remediation due Sep 7, 2022. View catalog ↗
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
blazeds <= 3.2coldfusion = 7.0.2coldfusion = 8.0coldfusion = 8.0.1coldfusion = 9.0flex_data_services = 2.0.1livecycle = 8.0.1livecycle = 8.2.1livecycle = 9.0livecycle_data_services = 2.5.1livecycle_data_services = 2.6.1livecycle_data_services = 3.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84397Medium· 5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields
CVE-2026-81975High· 7.8Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-79908High· 7.8Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-82001Medium· 5.5Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service
CVE-2026-81997Medium· 6.3Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass
CVE-2026-81996High· 8.8Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation