← Back

CVE-2018-1000828

nvd nist
Published: Dec 20, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.0
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.

Affected (92)

Products: Frostwire: Frostwire
1 product
Frostwire
Configuration A
92 vulnerable
Vulnerable SoftwareAffected Versions
Frostwire
Version 1.9.9 build246
Version 1.9.9 build247
Version 2.0.7 build263
Version 6.1.6 build166
Version 6.1.6 build167
Version 6.1.7 build168
Version 6.1.8 build169
Version 6.1.9 build172
Version 6.2.0 build173
Version 6.2.0 build174
Version 6.2.1 build175
Version 6.2.2 build176
Version 6.2.3 build177
Version 6.2.3 build178
Version 6.2.4 build179
Version 6.3.0 build180
Version 6.3.0 build181
Version 6.3.0 build182
Version 6.3.0 build183
Version 6.3.0 build184
Version 6.3.0 build185
Version 6.3.1 build186
Version 6.3.2 build187
Version 6.3.2 build188
Version 6.3.3 build189
Version 6.3.3 build190
Version 6.3.3 build193
Version 6.3.3 build255
Version 6.3.4 build193
Version 6.3.4 build194
Version 6.3.5 build195
Version 6.3.5 build197
Version 6.3.5 build198
Version 6.3.6 build201
Version 6.3.6 build202
Version 6.3.7 build203
Version 6.3.7 build204
Version 6.3.7 build205
Version 6.3.7 build206
Version 6.4.0 build207
Version 6.4.0 build208
Version 6.4.1 build209
Version 6.4.1 build210
Version 6.4.2 build212
Version 6.4.3 build214
Version 6.4.4 build215
Version 6.4.5 build218
Version 6.4.5 build219
Version 6.4.5 build220
Version 6.4.5 build221
Version 6.4.5 build222
Version 6.4.6 build223
Version 6.4.6 build227
Version 6.4.7 build228
Version 6.4.7 build229
Version 6.4.8 build230
Version 6.4.8 build232
Version 6.4.8 build233
Version 6.4.8 build234
Version 6.4.9 build235
Version 6.5.0 build236
Version 6.5.1 build238
Version 6.5.2 build239
Version 6.5.3 build240
Version 6.5.4 build241
Version 6.5.5 build242
Version 6.5.5 build243
Version 6.5.8 build244
Version 6.5.8 build245
Version 6.5.9 build246
Version 6.6.0 build248
Version 6.6.1 build249
Version 6.6.2 build250
Version 6.6.2 build251
Version 6.6.3 build252
Version 6.6.3 build253
Version 6.6.4 build256
Version 6.6.5 build257
Version 6.6.6 build258
Version 6.6.7 build529
Version 6.6.8 build260
Version 6.7.0 build261
Version 6.7.0 build262
Version 6.7.0 build264
Version 6.7.0 build265hotfix
Version 6.7.1 build266
Version 6.7.1 build267
Version 6.7.1 build268
Version 6.7.2 build269
Version 6.7.2 build270
Version 6.7.3 build271
Version 6.7.4 build272

References (4)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.