NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87193  CVE-2016-1000219  Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.    Medium  2017-06-28  2017-06-28  View
87194  CVE-2016-1000220  Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.    4.3  Medium  2017-06-28  2017-06-28  View
87195  CVE-2016-1000221  Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.          2017-06-23  2017-06-20  View
87196  CVE-2016-1000222  Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.          2017-06-18  2017-06-16  View
82880  CVE-2016-10003  Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.    Medium  2017-02-28  2017-02-27  View

Page 15334 of 17672, showing 5 records out of 88360 total, starting on record 76666, ending on 76670

Actions