NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 87212 | CVE-2016-10366 | Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-28 | View | |
| 87211 | CVE-2016-10365 | Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website. | 2 | 5.8 | Medium | 2017-06-28 | 2017-06-28 | View | |
| 87210 | CVE-2016-10364 | With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions. | 2017-06-18 | 2017-06-16 | View | ||||
| 87209 | CVE-2016-10363 | Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit. | 2017-06-18 | 2017-06-16 | View | ||||
| 87208 | CVE-2016-10362 | Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials. | 2017-06-23 | 2017-06-21 | View |
Page 2282 of 17672, showing 5 records out of 88360 total, starting on record 11406, ending on 11410