NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86645  CVE-2017-8439  Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.    4.3  Medium  2017-06-17  2017-06-13  View
86646  CVE-2017-8440  Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.    4.3  Medium  2017-06-17  2017-06-13  View
86647  CVE-2017-8441  Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.    Medium  2017-06-17  2017-06-13  View
86648  CVE-2017-8834  The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.    4.3  Medium  2017-06-17  2017-06-15  View
86649  CVE-2017-8835  SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.    7.5  High  2017-06-17  2017-06-12  View

Page 16184 of 17672, showing 5 records out of 88360 total, starting on record 80916, ending on 80920

Actions