NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20561 | CVE-2016-5229 | Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization. | 2 | 7.5 | High | 2017-01-19 | 2016-08-03 | View | |
85225 | CVE-2017-7415 | Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource. | 2 | 5 | Medium | 2017-05-27 | 2017-05-09 | View | |
28567 | CVE-2015-8399 | Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action. | 2 | 4 | Medium | 2017-01-19 | 2016-04-14 | View | |
87096 | CVE-2017-9505 | Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself. | 2 | 4 | Medium | 2017-07-18 | 2017-07-03 | View | |
39638 | CVE-2013-3925 | Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference. | 2 | 5.8 | Medium | 2017-01-18 | 2013-07-02 | View |
Page 1442 of 17672, showing 5 records out of 88360 total, starting on record 7206, ending on 7210