Show filters
501 Total Results
Displaying 431-440 of 501
Sort by:
Attacker Value
Unknown
CVE-2017-14591
Disclosure Date: November 29, 2017 (last updated November 26, 2024)
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
0
Attacker Value
Unknown
CVE-2017-14585
Disclosure Date: November 27, 2017 (last updated November 26, 2024)
A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hipchat Server starting with 2.2.0 and before 2.2.6 are affected by this vulnerability. Versions of Hipchat Data Center starting with 3.0.0 and before 3.1.0 are affected.
0
Attacker Value
Unknown
CVE-2017-14586
Disclosure Date: November 27, 2017 (last updated November 26, 2024)
The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and before version 4.30 are affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2017-9514
Disclosure Date: October 12, 2017 (last updated November 26, 2024)
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.
0
Attacker Value
Unknown
CVE-2017-14587
Disclosure Date: October 11, 2017 (last updated November 26, 2024)
The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.
0
Attacker Value
Unknown
CVE-2017-14588
Disclosure Date: October 11, 2017 (last updated November 26, 2024)
Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.
0
Attacker Value
Unknown
CVE-2015-6576
Disclosure Date: October 03, 2017 (last updated November 26, 2024)
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
0
Attacker Value
Unknown
CVE-2017-9511
Disclosure Date: August 24, 2017 (last updated October 16, 2024)
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.
0
Attacker Value
Unknown
CVE-2017-9510
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.
0
Attacker Value
Unknown
CVE-2017-9507
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.
0