diff --git a/2018/12xxx/CVE-2018-12240.json b/2018/12xxx/CVE-2018-12240.json index 33b274f37f3..46b4353e30d 100644 --- a/2018/12xxx/CVE-2018-12240.json +++ b/2018/12xxx/CVE-2018-12240.json @@ -35,7 +35,7 @@ "description_data" : [ { "lang" : "eng", - "value" : "The Norton Identity Safe product may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials." + "value" : "The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials." } ] }, @@ -54,6 +54,8 @@ "references" : { "reference_data" : [ { + "name" : "https://support.symantec.com/en_US/article.SYMSA1460.html", + "refsource" : "CONFIRM", "url" : "https://support.symantec.com/en_US/article.SYMSA1460.html" } ] diff --git a/2018/7xxx/CVE-2018-7789.json b/2018/7xxx/CVE-2018-7789.json index b6b519f1cb7..52da9d02826 100644 --- a/2018/7xxx/CVE-2018-7789.json +++ b/2018/7xxx/CVE-2018-7789.json @@ -54,6 +54,8 @@ "references" : { "reference_data" : [ { + "name" : "https://www.schneider-electric.com/en/download/document/SEVD-2018-233-01/", + "refsource" : "CONFIRM", "url" : "https://www.schneider-electric.com/en/download/document/SEVD-2018-233-01/" } ] diff --git a/2018/7xxx/CVE-2018-7795.json b/2018/7xxx/CVE-2018-7795.json index 4328636f376..fc57c07fe19 100644 --- a/2018/7xxx/CVE-2018-7795.json +++ b/2018/7xxx/CVE-2018-7795.json @@ -35,7 +35,7 @@ "description_data" : [ { "lang" : "eng", - "value" : "A Cross Protocol Injection vulnerability existis in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on itsweb browser. User inputs can be manipulated to cause execution of java script code." + "value" : "A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on itsweb browser. User inputs can be manipulated to cause execution of java script code." } ] }, @@ -54,6 +54,8 @@ "references" : { "reference_data" : [ { + "name" : "https://www.schneider-electric.com/en/download/document/SEVD-2018-228-01/", + "refsource" : "CONFIRM", "url" : "https://www.schneider-electric.com/en/download/document/SEVD-2018-228-01/" } ]