NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86646 | CVE-2017-8440 | Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-13 | View | |
86645 | CVE-2017-8439 | Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-13 | View | |
86644 | CVE-2017-8438 | Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. If a role has been created using a template that contains the _user properties, the behavior of run_as will be incorrect. Additionally if the run_as user specified does not exist, the transition will not happen. | 2 | 6.5 | Medium | 2017-06-17 | 2017-06-13 | View | |
86069 | CVE-2017-8422 | KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app. | 2 | 7.2 | High | 2017-07-18 | 2017-07-07 | View | |
85575 | CVE-2017-8421 | The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dump_relocs_in_section in objdump.c can resolve this. | 2 | 7.1 | High | 2017-05-27 | 2017-05-12 | View |
Page 170 of 17672, showing 5 records out of 88360 total, starting on record 846, ending on 850