CVE-2004-0407
Last modified
CVE-2004-0407 is a vulnerability of currently unknown severity. The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.. EPSS estimates a 1.53% chance of exploitation in the next 30 days.
Description
The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Macromedia | Coldfusion | 6.1 |
References
- http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.htmlPatch, Vendor Advisory
- http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0407?
How severe is CVE-2004-0407?
How do I fix CVE-2004-0407?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0401Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.…
- CVE-2004-0402Buffer overflow in xpcd-svga in xpcd before 2.08, and possib…
- CVE-2004-0403Racoon before 20040408a allows remote attackers to cause a d…
- CVE-2004-0404logcheck before 1.1.1 allows local users to overwrite arbitr…
- CVE-2004-0405CVS before 1.11 allows CVS clients to read arbitrary files v…
- CVE-2004-0406Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2004-0408Buffer overflow in the child_service function in the ident2 …
- CVE-2004-0409Stack-based buffer overflow in the Socks-5 proxy code for XC…
- CVE-2004-0410Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2004-0411The URI handlers in Konqueror for KDE 3.2.2 and earlier do n…
- CVE-2004-0412Mailman before 2.1.5 allows remote attackers to obtain user …
- CVE-2004-0413libsvn_ra_svn in Subversion 1.0.4 trusts the length field of…
Are you affected by CVE-2004-0407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
