diff --git a/2018/20xxx/CVE-2018-20340.json b/2018/20xxx/CVE-2018-20340.json new file mode 100644 index 00000000000..76d25c5af50 --- /dev/null +++ b/2018/20xxx/CVE-2018-20340.json @@ -0,0 +1,18 @@ +{ + "CVE_data_meta" : { + "ASSIGNER" : "cve@mitre.org", + "ID" : "CVE-2018-20340", + "STATE" : "RESERVED" + }, + "data_format" : "MITRE", + "data_type" : "CVE", + "data_version" : "4.0", + "description" : { + "description_data" : [ + { + "lang" : "eng", + "value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} diff --git a/2018/5xxx/CVE-2018-5201.json b/2018/5xxx/CVE-2018-5201.json index 9bb62aea7d4..345c61c6c79 100644 --- a/2018/5xxx/CVE-2018-5201.json +++ b/2018/5xxx/CVE-2018-5201.json @@ -34,7 +34,7 @@ "description_data" : [ { "lang" : "eng", - "value" : "Hancom Office 2018, Hancom Office NEO, Hancom Office 2014, Hancom Office 2010 have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions." + "value" : "Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions." } ] }, @@ -53,7 +53,8 @@ "references" : { "reference_data" : [ { - "refsource" : "CONFIRM", + "name" : "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30116", + "refsource" : "MISC", "url" : "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30116" } ] diff --git a/2018/5xxx/CVE-2018-5202.json b/2018/5xxx/CVE-2018-5202.json index a7e50cc25ba..8d78a776ccf 100644 --- a/2018/5xxx/CVE-2018-5202.json +++ b/2018/5xxx/CVE-2018-5202.json @@ -37,7 +37,7 @@ "description_data" : [ { "lang" : "eng", - "value" : "SKCertService contains a vulnerability that could allow remote attacker to execute arbitrary code. This vulnerability exists due to the way .dll files are loaded by SKCertService. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge." + "value" : "SKCertService 2.5.5 and earlier contains a vulnerability that could allow remote attacker to execute arbitrary code. This vulnerability exists due to the way .dll files are loaded by SKCertService. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge." } ] }, @@ -56,7 +56,8 @@ "references" : { "reference_data" : [ { - "refsource" : "CONFIRM", + "name" : "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30119", + "refsource" : "MISC", "url" : "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30119" } ]