diff --git a/2015/8xxx/CVE-2015-8277.json b/2015/8xxx/CVE-2015-8277.json index 96a97de0e1f..91bafaa0ac2 100644 --- a/2015/8xxx/CVE-2015-8277.json +++ b/2015/8xxx/CVE-2015-8277.json @@ -67,6 +67,16 @@ "refsource" : "MISC", "url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-102-02" }, + { + "name" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-212-05", + "refsource" : "MISC", + "url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-212-05" + }, + { + "name" : "https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec129.pdf", + "refsource" : "MISC", + "url" : "https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec129.pdf" + }, { "name" : "http://support.citrix.com/article/CTX207824", "refsource" : "CONFIRM", diff --git a/2015/9xxx/CVE-2015-9251.json b/2015/9xxx/CVE-2015-9251.json index 56ebac30442..fa136ea0868 100644 --- a/2015/9xxx/CVE-2015-9251.json +++ b/2015/9xxx/CVE-2015-9251.json @@ -76,6 +76,16 @@ "name" : "https://snyk.io/vuln/npm:jquery:20150627", "refsource" : "MISC", "url" : "https://snyk.io/vuln/npm:jquery:20150627" + }, + { + "name" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-212-04", + "refsource" : "MISC", + "url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-212-04" + }, + { + "name" : "https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec126.pdf", + "refsource" : "MISC", + "url" : "https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec126.pdf" } ] } diff --git a/2017/12xxx/CVE-2017-12614.json b/2017/12xxx/CVE-2017-12614.json index 691decdc3c5..90b1085879a 100644 --- a/2017/12xxx/CVE-2017-12614.json +++ b/2017/12xxx/CVE-2017-12614.json @@ -35,7 +35,7 @@ "description_data" : [ { "lang" : "eng", - "value" : "It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above. Credit: This issue was discovered by Seth Long at Credit Karma" + "value" : "It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above." } ] }, @@ -54,6 +54,8 @@ "references" : { "reference_data" : [ { + "name" : "[dev] 20180806 CVE-2017-12614 XSS Vulnerability in Airflow < 1.9", + "refsource" : "MLIST", "url" : "https://lists.apache.org/thread.html/2c72480c76619c5e7793f0d213c34082f0598eaa4d212172f068940f@%3Cdev.airflow.apache.org%3E" } ] diff --git a/2018/15xxx/CVE-2018-15120.json b/2018/15xxx/CVE-2018-15120.json new file mode 100644 index 00000000000..7ac8b300e0a --- /dev/null +++ b/2018/15xxx/CVE-2018-15120.json @@ -0,0 +1,18 @@ +{ + "CVE_data_meta" : { + "ASSIGNER" : "cve@mitre.org", + "ID" : "CVE-2018-15120", + "STATE" : "RESERVED" + }, + "data_format" : "MITRE", + "data_type" : "CVE", + "data_version" : "4.0", + "description" : { + "description_data" : [ + { + "lang" : "eng", + "value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} diff --git a/2018/1xxx/CVE-2018-1524.json b/2018/1xxx/CVE-2018-1524.json index 80c27458203..cece15656a5 100644 --- a/2018/1xxx/CVE-2018-1524.json +++ b/2018/1xxx/CVE-2018-1524.json @@ -62,7 +62,7 @@ "description_data" : [ { "lang" : "eng", - "value" : "IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116." + "value" : "IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116." } ] },