diff --git a/2018/12xxx/CVE-2018-12244.json b/2018/12xxx/CVE-2018-12244.json index 5ca9762f474..fb894fb5c92 100644 --- a/2018/12xxx/CVE-2018-12244.json +++ b/2018/12xxx/CVE-2018-12244.json @@ -1,17 +1,69 @@ { - "CVE_data_meta": { - "ASSIGNER": "cve@mitre.org", - "ID": "CVE-2018-12244", - "STATE": "RESERVED" - }, - "data_format": "MITRE", "data_type": "CVE", + "data_format": "MITRE", "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2018-12244", + "ASSIGNER": "secure@symantec.com", + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "vendor_name": "Symantec Corporation", + "product": { + "product_data": [ + { + "product_name": "Symantec Endpoint Protection (Mac Client)", + "version": { + "version_data": [ + { + "version_value": "Prior to and including 12.1 RU6 MP9" + }, + { + "version_value": "Prior to 14.2 RU1" + } + ] + } + } + ] + } + } + ] + } + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CSV/DDE Injection" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "MISC", + "name": "https://support.symantec.com/en_US/article.SYMSA1479.html", + "url": "https://support.symantec.com/en_US/article.SYMSA1479.html" + }, + { + "refsource": "BID", + "name": "107999", + "url": "https://www.securityfocus.com/bid/107999" + } + ] + }, "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files." } ] } diff --git a/2018/18xxx/CVE-2018-18286.json b/2018/18xxx/CVE-2018-18286.json index 8f84043355c..0499604a777 100644 --- a/2018/18xxx/CVE-2018-18286.json +++ b/2018/18xxx/CVE-2018-18286.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2018-18286", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://www.mitel.com/en-gb/support/security-advisories/mitel-product-security-adivsory-19-0003-001", + "url": "https://www.mitel.com/en-gb/support/security-advisories/mitel-product-security-adivsory-19-0003-001" + }, + { + "refsource": "CONFIRM", + "name": "https://www.mitel.com/-/media/mitel/pdf/security-advisories/security-bulletin-19-0003-001.pdf", + "url": "https://www.mitel.com/-/media/mitel/pdf/security-advisories/security-bulletin-19-0003-001.pdf" } ] } diff --git a/2018/20xxx/CVE-2018-20250.json b/2018/20xxx/CVE-2018-20250.json index 6dee0e868ea..44344fd1908 100644 --- a/2018/20xxx/CVE-2018-20250.json +++ b/2018/20xxx/CVE-2018-20250.json @@ -87,6 +87,11 @@ "refsource": "MISC", "name": "http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_ace", "url": "http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_ace" + }, + { + "refsource": "EXPLOIT-DB", + "name": "46756", + "url": "https://www.exploit-db.com/exploits/46756/" } ] } diff --git a/2019/10xxx/CVE-2019-10893.json b/2019/10xxx/CVE-2019-10893.json index 18d1a7d7508..8ed6ef73ce9 100644 --- a/2019/10xxx/CVE-2019-10893.json +++ b/2019/10xxx/CVE-2019-10893.json @@ -71,6 +71,11 @@ "refsource": "BID", "name": "108035", "url": "http://www.securityfocus.com/bid/108035" + }, + { + "refsource": "EXPLOIT-DB", + "name": "46669", + "url": "https://www.exploit-db.com/exploits/46669" } ] } diff --git a/2019/11xxx/CVE-2019-11536.json b/2019/11xxx/CVE-2019-11536.json new file mode 100644 index 00000000000..4a432b2a531 --- /dev/null +++ b/2019/11xxx/CVE-2019-11536.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2019-11536", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2019/11xxx/CVE-2019-11537.json b/2019/11xxx/CVE-2019-11537.json new file mode 100644 index 00000000000..4d1c618b262 --- /dev/null +++ b/2019/11xxx/CVE-2019-11537.json @@ -0,0 +1,77 @@ +{ + "CVE_data_meta": { + "ASSIGNER": "cve@mitre.org", + "ID": "CVE-2019-11537", + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } + }, + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", + "description": { + "description_data": [ + { + "lang": "eng", + "value": "In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclusion." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "url": "https://github.com/osTicket/osTicket/pull/4869", + "refsource": "MISC", + "name": "https://github.com/osTicket/osTicket/pull/4869" + }, + { + "url": "https://pentest.com.tr/exploits/osTicket-v1-11-XSS-to-LFI.html", + "refsource": "MISC", + "name": "https://pentest.com.tr/exploits/osTicket-v1-11-XSS-to-LFI.html" + }, + { + "url": "https://www.exploit-db.com/exploits/46753", + "refsource": "MISC", + "name": "https://www.exploit-db.com/exploits/46753" + }, + { + "url": "https://github.com/osTicket/osTicket/releases/tag/v1.12", + "refsource": "MISC", + "name": "https://github.com/osTicket/osTicket/releases/tag/v1.12" + } + ] + } +} \ No newline at end of file diff --git a/2019/9xxx/CVE-2019-9669.json b/2019/9xxx/CVE-2019-9669.json index 39a3b7206d0..fd7034b8086 100644 --- a/2019/9xxx/CVE-2019-9669.json +++ b/2019/9xxx/CVE-2019-9669.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-9669", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,28 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "MISC", + "name": "https://www.edgescan.com/popular-wordpress-waf-bypass-zeroday-discovered-by-edgescan/", + "url": "https://www.edgescan.com/popular-wordpress-waf-bypass-zeroday-discovered-by-edgescan/" } ] }