NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86646  CVE-2017-8440  Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.    4.3  Medium  2017-06-17  2017-06-13  View
86645  CVE-2017-8439  Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.    4.3  Medium  2017-06-17  2017-06-13  View
86644  CVE-2017-8438  Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. If a role has been created using a template that contains the _user properties, the behavior of run_as will be incorrect. Additionally if the run_as user specified does not exist, the transition will not happen.    6.5  Medium  2017-06-17  2017-06-13  View
86069  CVE-2017-8422  KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.    7.2  High  2017-07-18  2017-07-07  View
85575  CVE-2017-8421  The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dump_relocs_in_section in objdump.c can resolve this.    7.1  High  2017-05-27  2017-05-12  View

Page 170 of 17672, showing 5 records out of 88360 total, starting on record 846, ending on 850

Actions