NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87208  CVE-2016-10362  Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.          2017-06-23  2017-06-21  View
87209  CVE-2016-10363  Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.          2017-06-18  2017-06-16  View
87210  CVE-2016-10364  With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.          2017-06-18  2017-06-16  View
87211  CVE-2016-10365  Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.    5.8  Medium  2017-06-28  2017-06-28  View
87212  CVE-2016-10366  Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.    4.3  Medium  2017-06-28  2017-06-28  View

Page 15391 of 17672, showing 5 records out of 88360 total, starting on record 76951, ending on 76955

Actions