NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87193 | CVE-2016-1000219 | Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield. | 2 | 5 | Medium | 2017-06-28 | 2017-06-28 | View | |
87194 | CVE-2016-1000220 | Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-28 | View | |
82341 | CVE-2016-5801 | An issue was discovered in OmniMetrix OmniView, Version 1.2. Insufficient password requirements for the OmniView web application may allow an attacker to gain access by brute forcing account passwords. | 2 | 5 | Medium | 2017-06-28 | 2017-06-28 | View | |
87211 | CVE-2016-10365 | Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website. | 2 | 5.8 | Medium | 2017-06-28 | 2017-06-28 | View | |
87212 | CVE-2016-10366 | Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-28 | View |
Page 16293 of 17672, showing 5 records out of 88360 total, starting on record 81461, ending on 81465