Show filters
501 Total Results
Displaying 461-470 of 501
Sort by:
Attacker Value
Unknown

CVE-2016-6283

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
0
Attacker Value
Unknown

CVE-2016-6496

Disclosure Date: December 09, 2016 (last updated November 25, 2024)
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
0
Attacker Value
Unknown

CVE-2016-5229

Disclosure Date: August 02, 2016 (last updated November 25, 2024)
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
0
Attacker Value
Unknown

CVE-2015-8398

Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
0
Attacker Value
Unknown

CVE-2015-8399

Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.
0
Attacker Value
Unknown

CVE-2015-8361

Disclosure Date: February 08, 2016 (last updated November 25, 2024)
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.
0
Attacker Value
Unknown

CVE-2014-9757

Disclosure Date: February 08, 2016 (last updated November 25, 2024)
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.
0
Attacker Value
Unknown

CVE-2015-8360

Disclosure Date: February 08, 2016 (last updated November 25, 2024)
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.
0
Attacker Value
Unknown

CVE-2015-8481

Disclosure Date: January 08, 2016 (last updated November 25, 2024)
Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote attackers to obtain sensitive information by updating a different issue that includes wiki markup for an external image reference.
0
Attacker Value
Unknown

CVE-2015-5603

Disclosure Date: September 21, 2015 (last updated October 05, 2023)
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability."
0