|
266241
|
7.5 |
HIGH
Network
|
elastic
|
logstash
|
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2016-1000221
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266242
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000220
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266243
|
7.5 |
HIGH
Network
|
elastic
|
kibana
|
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack session…
|
CWE-285
Improper Authorization
|
CVE-2016-1000219
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266244
|
8.8 |
HIGH
Network
|
elastic
|
kibana_reporting
|
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially…
|
CWE-352
Origin Validation Error
|
CVE-2016-1000218
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266245
|
7.8 |
HIGH
Local
|
flexerasoftware
|
flexnet_publisher
|
In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licen…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10395
|
2024-11-21 11:43 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266246
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10342
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266247
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10341
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266248
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10340
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266249
|
7.1 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.
|
CWE-200
Information Exposure
|
CVE-2016-10339
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266250
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
|
CWE-20
Improper Input Validation
|
CVE-2016-10338
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|