NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87195 | CVE-2016-1000221 | Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information. | 2017-06-23 | 2017-06-20 | View | ||||
87194 | CVE-2016-1000220 | Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-28 | View | |
87193 | CVE-2016-1000219 | Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield. | 2 | 5 | Medium | 2017-06-28 | 2017-06-28 | View | |
87192 | CVE-2016-1000218 | Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially-crafted page. | 2017-06-28 | 2017-06-26 | View | ||||
87191 | CVE-2015-9097 | The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring. | 2017-06-18 | 2017-06-12 | View |
Page 234 of 17672, showing 5 records out of 88360 total, starting on record 1166, ending on 1170