Show filters
501 Total Results
Displaying 371-380 of 501
Sort by:
Attacker Value
Unknown
CVE-2018-13389
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.
0
Attacker Value
Unknown
CVE-2018-1000617
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
Atlassian Floodlight Atlassian Floodlight Controller version 1.2 and earlier versions contains a Denial of Service vulnerability in Forwarding module that can result in Improper type cast in Forwarding module allows remote attackers to cause a DoS(thread crash).. This attack appear to be exploitable via network connectivity (Remote attack).
0
Attacker Value
Unknown
CVE-2018-11429
Disclosure Date: July 04, 2018 (last updated November 27, 2024)
ATLANT (ATL) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.
0
Attacker Value
Unknown
CVE-2017-16859
Disclosure Date: June 28, 2018 (last updated November 26, 2024)
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.
0
Attacker Value
Unknown
CVE-2018-5231
Disclosure Date: May 16, 2018 (last updated November 26, 2024)
The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to perform a denial of service attack via sending requests to it.
0
Attacker Value
Unknown
CVE-2018-5230
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value is specified.
0
Attacker Value
Unknown
CVE-2017-16860
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
The invalidRedirectUrl template in Atlassian Application Links before version 5.2.7, from version 5.3.0 before version 5.3.4 and from version 5.4.0 before version 5.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the redirectUrl parameter link in the redirect warning message.
0
Attacker Value
Unknown
CVE-2018-5226
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. All versions of Sourcetree for Windows before 2.5.5.0 are affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2018-5228
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.
0
Attacker Value
Unknown
CVE-2017-18102
Disclosure Date: April 17, 2018 (last updated November 26, 2024)
The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup.
0