{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-01T15:55:14.399","vulnerabilities":[{"cve":{"id":"CVE-2018-4938","sourceIdentifier":"psirt@adobe.com","published":"2018-05-19T17:29:01.433","lastModified":"2025-05-06T15:15:56.700","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation could lead to local privilege escalation."},{"lang":"es","value":"Adobe ColdFusion Update 5 y anteriores y ColdFusion 11 Update 13 y anteriores tienen una vulnerabilidad explotable de carga de biblioteca no segura. Su explotación con éxito podría conducir al escalado de privilegios locales."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-427"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-427"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:-:*:*:*:*:*:*","matchCriteriaId":"E217CE63-07DC-4A88-8877-181F33A21C20"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update1:*:*:*:*:*:*","matchCriteriaId":"7D4BD25E-6856-40EC-98A8-ACB540992487"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update10:*:*:*:*:*:*","matchCriteriaId":"2F0907E8-7BC4-4F5A-894C-B7C5F6BAAEAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update11:*:*:*:*:*:*","matchCriteriaId":"AFE18FEA-271A-42FE-8C24-19731DEB5444"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update12:*:*:*:*:*:*","matchCriteriaId":"15F7DCF1-D9F2-45C0-B089-E37C91579729"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update13:*:*:*:*:*:*","matchCriteriaId":"CB398297-DA76-4A56-858B-FC69FF220DAF"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update2:*:*:*:*:*:*","matchCriteriaId":"82F81CF8-1482-4731-AD34-677B8D6B930B"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update3:*:*:*:*:*:*","matchCriteriaId":"57BBBE71-BBE0-4129-B997-3F9AF54BFBD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update4:*:*:*:*:*:*","matchCriteriaId":"8E514D95-9287-4A43-9A44-BD6F8EDC5DA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update5:*:*:*:*:*:*","matchCriteriaId":"96C50CD1-CE75-4D70-AD65-2DB6027D806A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update6:*:*:*:*:*:*","matchCriteriaId":"AE1B1190-4699-4FB0-AD46-DF0233B5BA90"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update7:*:*:*:*:*:*","matchCriteriaId":"827CB550-5078-4FD5-8B1F-616C06912AD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update8:*:*:*:*:*:*","matchCriteriaId":"31F22450-F26C-4797-9292-66CA444C0D2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:11.0:update9:*:*:*:*:*:*","matchCriteriaId":"72450205-B4F4-4B44-9991-F4876D829BBD"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2016:-:*:*:*:*:*:*","matchCriteriaId":"B262F442-FF7F-4CC0-A9C5-FFD0EDB08E38"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2016:update1:*:*:*:*:*:*","matchCriteriaId":"9F3D7C8E-6695-44DF-AC9A-1AE09C46C529"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2016:update2:*:*:*:*:*:*","matchCriteriaId":"12BAE66C-A745-4661-B5BB-7FC2C169CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2016:update3:*:*:*:*:*:*","matchCriteriaId":"E6EC92F3-1EF8-4820-9CD8-ECEA03D27A7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2016:update4:*:*:*:*:*:*","matchCriteriaId":"D7446D70-D616-4EC1-BC64-41CDE56EFEAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2016:update5:*:*:*:*:*:*","matchCriteriaId":"59453B01-EAAF-4291-B2C2-98835F5AFE80"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/103718","source":"psirt@adobe.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb18-14.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/103718","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb18-14.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}