U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2016-1114

Change History

Modified Analysis by NIST 5/14/2020 3:27:35 PM

Action Type Old Value New Value
Changed CPE Configuration
OR
     *cpe:2.3:a:adobe:coldfusion:*:update_18:*:*:*:*:*:* versions up to (including) 10.0
     *cpe:2.3:a:adobe:coldfusion:*:update_7:*:*:*:*:*:* versions up to (including) 11.0
     *cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:* versions up to (including) 2016.00
OR
     *cpe:2.3:a:adobe:coldfusion:10.0:-:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_1:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_10:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_11:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_12:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_13:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_14:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_15:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_16:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_17:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_18:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_2:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_3:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_4:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_5:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_6:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_7:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_8:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:10.0:update_9:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:11.0:-:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:11.0:update_1:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:11.0:update_2:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:11.0:update_3:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:11.0:update_4:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:11.0:update_5:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:11.0:update_6:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:11.0:update_7:*:*:*:*:*:*
     *cpe:2.3:a:adobe:coldfusion:2016:-:*:*:*:*:*:*
Removed CVSS V3
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

								
						
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-502
Removed CWE
NIST NVD-CWE-Other

								
						
Removed Evaluator Description
<a href="http://cwe.mitre.org/data/definitions/502.html">CWE-502: Deserialization of Untrusted Data</a>

								
						
Changed Reference Type
http://www.securityfocus.com/bid/90506 No Types Assigned
http://www.securityfocus.com/bid/90506 Third Party Advisory, VDB Entry