diff --git a/2018/0xxx/CVE-2018-0618.json b/2018/0xxx/CVE-2018-0618.json index 13b0a286b2d..cc1ecfbf6fc 100644 --- a/2018/0xxx/CVE-2018-0618.json +++ b/2018/0xxx/CVE-2018-0618.json @@ -71,6 +71,11 @@ "name": "JVN#00846677", "refsource": "JVN", "url": "http://jvn.jp/en/jp/JVN00846677/index.html" + }, + { + "refsource": "GENTOO", + "name": "GLSA-201904-10", + "url": "https://security.gentoo.org/glsa/201904-10" } ] } diff --git a/2018/13xxx/CVE-2018-13796.json b/2018/13xxx/CVE-2018-13796.json index d42d0cdd421..c660ee26101 100644 --- a/2018/13xxx/CVE-2018-13796.json +++ b/2018/13xxx/CVE-2018-13796.json @@ -66,6 +66,11 @@ "name": "[mailman-users] 20180710 Re: correction: Mailman 2.1.28 Security fix release", "refsource": "MLIST", "url": "https://www.mail-archive.com/mailman-users@python.org/msg71003.html" + }, + { + "refsource": "GENTOO", + "name": "GLSA-201904-10", + "url": "https://security.gentoo.org/glsa/201904-10" } ] } diff --git a/2019/10xxx/CVE-2019-10676.json b/2019/10xxx/CVE-2019-10676.json index f259d2d30f8..55108f8fcfd 100644 --- a/2019/10xxx/CVE-2019-10676.json +++ b/2019/10xxx/CVE-2019-10676.json @@ -1,17 +1,76 @@ { - "data_type": "CVE", - "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { - "ID": "CVE-2019-10676", "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "ID": "CVE-2019-10676", + "STATE": "PUBLIC" }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } + }, + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in Uniqkey Password Manager 1.14. Upon entering new credentials to a site that is not registered within this product, a pop-up window will appear prompting the user if they want to save this new password. This pop-up window will persist on any page the user enters within the browser until a decision is made. The code of the pop-up window can be read by remote servers and contains the login credentials and URL in cleartext. A malicious server could easily grab this information from the pop-up. This is related to id=\"uniqkey-password-popup\" and password-popup/popup.html." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "MISC", + "name": "https://seclists.org/fulldisclosure/2019/Apr/1", + "url": "https://seclists.org/fulldisclosure/2019/Apr/1" + }, + { + "refsource": "MISC", + "name": "https://packetstormsecurity.com/files/152410/Uniqkey-Password-Manager-1.14-Credential-Disclosure.html", + "url": "https://packetstormsecurity.com/files/152410/Uniqkey-Password-Manager-1.14-Credential-Disclosure.html" + }, + { + "refsource": "MISC", + "name": "https://cxsecurity.com/issue/WLB-2019040055", + "url": "https://cxsecurity.com/issue/WLB-2019040055" + }, + { + "refsource": "MISC", + "name": "https://vuldb.com/?id.132740", + "url": "https://vuldb.com/?id.132740" } ] } diff --git a/2019/11xxx/CVE-2019-11000.json b/2019/11xxx/CVE-2019-11000.json new file mode 100644 index 00000000000..963e144ee96 --- /dev/null +++ b/2019/11xxx/CVE-2019-11000.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2019-11000", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2019/11xxx/CVE-2019-11001.json b/2019/11xxx/CVE-2019-11001.json new file mode 100644 index 00000000000..8ecd6d1eed3 --- /dev/null +++ b/2019/11xxx/CVE-2019-11001.json @@ -0,0 +1,67 @@ +{ + "CVE_data_meta": { + "ASSIGNER": "cve@mitre.org", + "ID": "CVE-2019-11001", + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } + }, + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", + "description": { + "description_data": [ + { + "lang": "eng", + "value": "On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the \"TestEmail\" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "url": "https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/", + "refsource": "MISC", + "name": "https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/" + }, + { + "url": "https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py", + "refsource": "MISC", + "name": "https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py" + } + ] + } +} \ No newline at end of file