NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87193  CVE-2016-1000219  Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.    Medium  2017-06-28  2017-06-28  View
87449  CVE-2014-8127  LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.          2017-06-28  2017-06-27  View
87194  CVE-2016-1000220  Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.    4.3  Medium  2017-06-28  2017-06-28  View
87450  CVE-2014-8149  OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.          2017-06-28  2017-06-27  View
83355  CVE-2017-6445  The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.    7.6  High  2017-06-28  2017-06-25  View

Page 1407 of 17672, showing 5 records out of 88360 total, starting on record 7031, ending on 7035

Actions