NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
20561  CVE-2016-5229  Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.    7.5  High  2017-01-19  2016-08-03  View
85225  CVE-2017-7415  Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.    Medium  2017-05-27  2017-05-09  View
28567  CVE-2015-8399  Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.    Medium  2017-01-19  2016-04-14  View
87096  CVE-2017-9505  Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.    Medium  2017-07-18  2017-07-03  View
39638  CVE-2013-3925  Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.    5.8  Medium  2017-01-18  2013-07-02  View

Page 1442 of 17672, showing 5 records out of 88360 total, starting on record 7206, ending on 7210

Actions