"-Synchronized-Data."

This commit is contained in:
CVE Team 2019-04-11 21:00:41 +00:00
parent b831eafec7
commit 88c7b22452
No known key found for this signature in database
GPG Key ID: 0DA1F9F56BC892E8
7 changed files with 193 additions and 20 deletions

View File

@ -37,7 +37,7 @@
"description_data": [
{
"lang": "eng",
"value": "OWASP OWASP ANTISAMY version 1.5.7 and earlier contains a Cross Site Scripting (XSS) vulnerability in AntiSamy.scan() - for both SAX & DOM that can result in Cross Site Scripting."
"value": "** DISPUTED ** OWASP OWASP ANTISAMY version 1.5.7 and earlier contains a Cross Site Scripting (XSS) vulnerability in AntiSamy.scan() - for both SAX & DOM that can result in Cross Site Scripting. NOTE: This has been disputed as a false positive."
}
]
},

View File

@ -53,9 +53,14 @@
"references": {
"reference_data": [
{
"url": "https://blog.mybb.com/2019/02/27/mybb-1-8-20-released-security-maintenance-release/",
"refsource": "MISC",
"name": "https://blog.mybb.com/2019/02/27/mybb-1-8-20-released-security-maintenance-release/"
"refsource": "CONFIRM",
"name": "https://blog.mybb.com/2019/02/27/mybb-1-8-20-released-security-maintenance-release/",
"url": "https://blog.mybb.com/2019/02/27/mybb-1-8-20-released-security-maintenance-release/"
},
{
"refsource": "CONFIRM",
"name": "https://github.com/mybb/mybb/blob/feature/SECURITY.md#technical-details-of-known-issues",
"url": "https://github.com/mybb/mybb/blob/feature/SECURITY.md#technical-details-of-known-issues"
}
]
}

View File

@ -2,7 +2,30 @@
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2018-20487",
"STATE": "RESERVED"
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
@ -11,7 +34,33 @@
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC method call to add a firewall rule as an \"include\" and point the \"path\" argument to a malicious script or binary. This gets executed as root when the firewall changes are committed."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://neonsea.uk/blog/2018/12/26/firewall-includes.html",
"refsource": "MISC",
"name": "https://neonsea.uk/blog/2018/12/26/firewall-includes.html"
},
{
"refsource": "CONFIRM",
"name": "http://public.inteno.se/?p=feed-inteno-openwrt.git;a=commit;h=e6159ca928d7f0c143be213afc6bf810c0329fe2",
"url": "http://public.inteno.se/?p=feed-inteno-openwrt.git;a=commit;h=e6159ca928d7f0c143be213afc6bf810c0329fe2"
}
]
}

View File

@ -61,6 +61,11 @@
"name": "20180330 CVE-2018-5708",
"refsource": "FULLDISC",
"url": "http://seclists.org/fulldisclosure/2018/Mar/66"
},
{
"refsource": "CONFIRM",
"name": "https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10111",
"url": "https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10111"
}
]
}

View File

@ -1,17 +1,61 @@
{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2019-6525",
"STATE": "RESERVED"
},
"data_format": "MITRE",
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2019-6525",
"ASSIGNER": "ics-cert@hq.dhs.gov",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "AVEVA",
"product": {
"product_data": [
{
"product_name": "Wonderware System Platform",
"version": {
"version_data": [
{
"version_value": "2017 Update 2 and prior"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "INSUFFICIENTLY PROTECTED CREDENTIALS CWE-522"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://ics-cert.us-cert.gov/advisories/ICSA-19-029-03",
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-029-03"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account."
}
]
}

View File

@ -1,17 +1,82 @@
{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2019-6534",
"STATE": "RESERVED"
},
"data_format": "MITRE",
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2019-6534",
"ASSIGNER": "ics-cert@hq.dhs.gov",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Gemalto",
"product": {
"product_data": [
{
"product_name": "Sentinel UltraPro",
"version": {
"version_data": [
{
"version_value": "Client Library ux32w.dll Version 1.3.0"
},
{
"version_value": "Client Library ux32w.dll Version 1.3.1"
},
{
"version_value": "Client Library ux32w.dll Version 1.3.2"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "UNCONTROLLED SEARCH PATH ELEMENT CWE-427"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://ics-cert.us-cert.gov/advisories/ICSA-19-073-02",
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-073-02"
},
{
"refsource": "MISC",
"name": "https://ics-cert.us-cert.gov/advisories/ICSA-19-078-01",
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-078-01"
},
{
"refsource": "MISC",
"name": "https://supportportal.gemalto.com/csm?id=kb_article_view&sysparm_article=KB0017694",
"url": "https://supportportal.gemalto.com/csm?id=kb_article_view&sysparm_article=KB0017694"
},
{
"refsource": "CONFIRM",
"name": "https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec131.pdf",
"url": "https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec131.pdf"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enables an attacker to load and execute a malicious file."
}
]
}

View File

@ -76,6 +76,11 @@
"refsource": "MLIST",
"name": "[james-server-dev] 20190318 [james-project] 01/03: JAMES-2693 Update com.puppycrawl.tools:checkstyle to respond to CVE-2019-9658",
"url": "https://lists.apache.org/thread.html/7eea10e7be4c21060cb1e79f6524c6e6559ba833b1465cd2870a56b9@%3Cserver-dev.james.apache.org%3E"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2019-a3f67e2364",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AEYBAHYAV37WHMOXZYM2ZWF46FHON6YC/"
}
]
}