diff --git a/2013/6xxx/CVE-2013-6364.json b/2013/6xxx/CVE-2013-6364.json index ae54b4dbfe3..381a6cee3c2 100644 --- a/2013/6xxx/CVE-2013-6364.json +++ b/2013/6xxx/CVE-2013-6364.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2013-6364", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,53 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book" + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "url": "https://security-tracker.debian.org/tracker/CVE-2013-6364", + "refsource": "MISC", + "name": "https://security-tracker.debian.org/tracker/CVE-2013-6364" + }, + { + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6364", + "refsource": "MISC", + "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6364" + }, + { + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6364", + "refsource": "MISC", + "name": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6364" + }, + { + "url": "http://archives.neohapsis.com/archives/bugtraq/2013-11/0012.html", + "refsource": "MISC", + "name": "http://archives.neohapsis.com/archives/bugtraq/2013-11/0012.html" + }, + { + "refsource": "MISC", + "name": "http://www.exploit-db.com/exploits/29519", + "url": "http://www.exploit-db.com/exploits/29519" + }, + { + "refsource": "MISC", + "name": "https://www.securityfocus.com/archive/1/529589", + "url": "https://www.securityfocus.com/archive/1/529589" } ] } diff --git a/2013/6xxx/CVE-2013-6365.json b/2013/6xxx/CVE-2013-6365.json index 3823dffb9ea..56d66e4910d 100644 --- a/2013/6xxx/CVE-2013-6365.json +++ b/2013/6xxx/CVE-2013-6365.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2013-6365", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,53 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions" + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "url": "https://security-tracker.debian.org/tracker/CVE-2013-6365", + "refsource": "MISC", + "name": "https://security-tracker.debian.org/tracker/CVE-2013-6365" + }, + { + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6365", + "refsource": "MISC", + "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6365" + }, + { + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6365", + "refsource": "MISC", + "name": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6365" + }, + { + "refsource": "MISC", + "name": "http://archives.neohapsis.com/archives/bugtraq/2013-11/0013.html", + "url": "http://archives.neohapsis.com/archives/bugtraq/2013-11/0013.html" + }, + { + "refsource": "MISC", + "name": "https://www.securityfocus.com/archive/1/529590", + "url": "https://www.securityfocus.com/archive/1/529590" + }, + { + "refsource": "MISC", + "name": "https://packetstormsecurity.com/files/cve/CVE-2013-6365", + "url": "https://packetstormsecurity.com/files/cve/CVE-2013-6365" } ] } diff --git a/2016/1000xxx/CVE-2016-1000002.json b/2016/1000xxx/CVE-2016-1000002.json index ac7a1998a42..c6ba286481d 100644 --- a/2016/1000xxx/CVE-2016-1000002.json +++ b/2016/1000xxx/CVE-2016-1000002.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2016-1000002", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,43 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "gdm3 3.14.2 and possibly later has an information leak before screen lock" + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "url": "https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000002.json", + "refsource": "MISC", + "name": "https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000002.json" + }, + { + "url": "https://security-tracker.debian.org/tracker/CVE-2016-1000002", + "refsource": "MISC", + "name": "https://security-tracker.debian.org/tracker/CVE-2016-1000002" + }, + { + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000002", + "refsource": "MISC", + "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000002" + }, + { + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2016-1000002", + "refsource": "MISC", + "name": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2016-1000002" } ] } diff --git a/2019/17xxx/CVE-2019-17221.json b/2019/17xxx/CVE-2019-17221.json new file mode 100644 index 00000000000..2bab8b77705 --- /dev/null +++ b/2019/17xxx/CVE-2019-17221.json @@ -0,0 +1,62 @@ +{ + "CVE_data_meta": { + "ASSIGNER": "cve@mitre.org", + "ID": "CVE-2019-17221", + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } + }, + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", + "description": { + "description_data": [ + { + "lang": "eng", + "value": "PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a given callback. An attacker can supply a specially crafted HTML file, as user input, that allows reading arbitrary files on the filesystem. For example, if page.render() is the function callback, this generates a PDF or an image of the targeted file. NOTE: this product is no longer developed." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "MISC", + "name": "https://www.darkmatter.ae/blogs/breaching-the-perimeter-phantomjs-arbitrary-file-read/", + "url": "https://www.darkmatter.ae/blogs/breaching-the-perimeter-phantomjs-arbitrary-file-read/" + } + ] + } +} \ No newline at end of file