NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 87193 | CVE-2016-1000219 | Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield. | 2 | 5 | Medium | 2017-06-28 | 2017-06-28 | View | |
| 87194 | CVE-2016-1000220 | Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-28 | View | |
| 87195 | CVE-2016-1000221 | Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information. | 2017-06-23 | 2017-06-20 | View | ||||
| 87196 | CVE-2016-1000222 | Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data. | 2017-06-18 | 2017-06-16 | View | ||||
| 82880 | CVE-2016-10003 | Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients. | 2 | 5 | Medium | 2017-02-28 | 2017-02-27 | View |
Page 15334 of 17672, showing 5 records out of 88360 total, starting on record 76666, ending on 76670