NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28532 | CVE-2015-8357 | Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or cause a denial of service, via a .. (dot dot) in the file parameter to admin/bitrix.xscan_worker.php. | 2 | 6.5 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 28533 | CVE-2015-8358 | Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the "work" array parameter to admin/bitrix.mpbuilder_step2.php. | 2 | 9 | High | 2017-01-19 | 2016-12-07 | View | |
| 28534 | CVE-2015-8360 | An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port. | 2 | 7.5 | High | 2017-01-19 | 2016-02-19 | View | |
| 28535 | CVE-2015-8361 | Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port. | 2 | 6.4 | Medium | 2017-01-19 | 2016-02-19 | View | |
| 28536 | CVE-2015-8362 | The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984. | 2 | 10 | High | 2017-01-19 | 2016-12-07 | View |
Page 15043 of 17672, showing 5 records out of 88360 total, starting on record 75211, ending on 75215