Show filters
501 Total Results
Displaying 391-400 of 501
Sort by:
Attacker Value
Unknown

CVE-2015-6569

Disclosure Date: February 21, 2018 (last updated November 26, 2024)
Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack.
0
Attacker Value
Unknown

CVE-2017-18095

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.
0
Attacker Value
Unknown

CVE-2017-18093

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository.
0
Attacker Value
Unknown

CVE-2017-18092

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet.
0
Attacker Value
Unknown

CVE-2017-18089

Disclosure Date: February 16, 2018 (last updated November 26, 2024)
The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.
0
Attacker Value
Unknown

CVE-2017-18090

Disclosure Date: February 16, 2018 (last updated November 26, 2024)
Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.
0
Attacker Value
Unknown

CVE-2017-18091

Disclosure Date: February 16, 2018 (last updated November 26, 2024)
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the filename of a backup.
0
Attacker Value
Unknown

CVE-2017-18087

Disclosure Date: February 15, 2018 (last updated November 26, 2024)
The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or determine if an internal service exists via an argument injection vulnerability in the at parameter.
0
Attacker Value
Unknown

CVE-2017-18088

Disclosure Date: February 15, 2018 (last updated November 26, 2024)
Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version 5.7.0 before 5.7.1 (the fixed version for 5.7.x) and before 5.8.0 allow remote attackers to conduct clickjacking attacks via framing various resources that lacked clickjacking protection.
0
Attacker Value
Unknown

CVE-2017-18084

Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
0