9

CVE-2018-1000828

FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FrostwireFrostwire Version1.9.9 Updatebuild246 SwPlatformdesktop
FrostwireFrostwire Version1.9.9 Updatebuild247 SwPlatformdesktop
FrostwireFrostwire Version2.0.7 Updatebuild263 SwPlatformdesktop
FrostwireFrostwire Version6.1.6 Updatebuild166 SwPlatformdesktop
FrostwireFrostwire Version6.1.6 Updatebuild167 SwPlatformdesktop
FrostwireFrostwire Version6.1.7 Updatebuild168 SwPlatformdesktop
FrostwireFrostwire Version6.1.8 Updatebuild169 SwPlatformdesktop
FrostwireFrostwire Version6.1.9 Updatebuild172 SwPlatformdesktop
FrostwireFrostwire Version6.2.0 Updatebuild173 SwPlatformdesktop
FrostwireFrostwire Version6.2.0 Updatebuild174 SwPlatformdesktop
FrostwireFrostwire Version6.2.1 Updatebuild175 SwPlatformdesktop
FrostwireFrostwire Version6.2.2 Updatebuild176 SwPlatformdesktop
FrostwireFrostwire Version6.2.3 Updatebuild177 SwPlatformdesktop
FrostwireFrostwire Version6.2.3 Updatebuild178 SwPlatformdesktop
FrostwireFrostwire Version6.2.4 Updatebuild179 SwPlatformdesktop
FrostwireFrostwire Version6.3.0 Updatebuild180 SwPlatformdesktop
FrostwireFrostwire Version6.3.0 Updatebuild181 SwPlatformdesktop
FrostwireFrostwire Version6.3.0 Updatebuild182 SwPlatformdesktop
FrostwireFrostwire Version6.3.0 Updatebuild183 SwPlatformdesktop
FrostwireFrostwire Version6.3.0 Updatebuild184 SwPlatformdesktop
FrostwireFrostwire Version6.3.0 Updatebuild185 SwPlatformdesktop
FrostwireFrostwire Version6.3.1 Updatebuild186 SwPlatformdesktop
FrostwireFrostwire Version6.3.2 Updatebuild187 SwPlatformdesktop
FrostwireFrostwire Version6.3.2 Updatebuild188 SwPlatformdesktop
FrostwireFrostwire Version6.3.3 Updatebuild189 SwPlatformdesktop
FrostwireFrostwire Version6.3.3 Updatebuild190 SwPlatformdesktop
FrostwireFrostwire Version6.3.3 Updatebuild193 SwPlatformdesktop
FrostwireFrostwire Version6.3.3 Updatebuild255 SwPlatformdesktop
FrostwireFrostwire Version6.3.4 Updatebuild193 SwPlatformdesktop
FrostwireFrostwire Version6.3.4 Updatebuild194 SwPlatformdesktop
FrostwireFrostwire Version6.3.5 Updatebuild195 SwPlatformdesktop
FrostwireFrostwire Version6.3.5 Updatebuild197 SwPlatformdesktop
FrostwireFrostwire Version6.3.5 Updatebuild198 SwPlatformdesktop
FrostwireFrostwire Version6.3.6 Updatebuild201 SwPlatformdesktop
FrostwireFrostwire Version6.3.6 Updatebuild202 SwPlatformdesktop
FrostwireFrostwire Version6.3.7 Updatebuild203 SwPlatformdesktop
FrostwireFrostwire Version6.3.7 Updatebuild204 SwPlatformdesktop
FrostwireFrostwire Version6.3.7 Updatebuild205 SwPlatformdesktop
FrostwireFrostwire Version6.3.7 Updatebuild206 SwPlatformdesktop
FrostwireFrostwire Version6.4.0 Updatebuild207 SwPlatformdesktop
FrostwireFrostwire Version6.4.0 Updatebuild208 SwPlatformdesktop
FrostwireFrostwire Version6.4.1 Updatebuild209 SwPlatformdesktop
FrostwireFrostwire Version6.4.1 Updatebuild210 SwPlatformdesktop
FrostwireFrostwire Version6.4.2 Updatebuild212 SwPlatformdesktop
FrostwireFrostwire Version6.4.3 Updatebuild214 SwPlatformdesktop
FrostwireFrostwire Version6.4.4 Updatebuild215 SwPlatformdesktop
FrostwireFrostwire Version6.4.5 Updatebuild218 SwPlatformdesktop
FrostwireFrostwire Version6.4.5 Updatebuild219 SwPlatformdesktop
FrostwireFrostwire Version6.4.5 Updatebuild220 SwPlatformdesktop
FrostwireFrostwire Version6.4.5 Updatebuild221 SwPlatformdesktop
FrostwireFrostwire Version6.4.5 Updatebuild222 SwPlatformdesktop
FrostwireFrostwire Version6.4.6 Updatebuild223 SwPlatformdesktop
FrostwireFrostwire Version6.4.6 Updatebuild227 SwPlatformdesktop
FrostwireFrostwire Version6.4.7 Updatebuild228 SwPlatformdesktop
FrostwireFrostwire Version6.4.7 Updatebuild229 SwPlatformdesktop
FrostwireFrostwire Version6.4.8 Updatebuild230 SwPlatformdesktop
FrostwireFrostwire Version6.4.8 Updatebuild232 SwPlatformdesktop
FrostwireFrostwire Version6.4.8 Updatebuild233 SwPlatformdesktop
FrostwireFrostwire Version6.4.8 Updatebuild234 SwPlatformdesktop
FrostwireFrostwire Version6.4.9 Updatebuild235 SwPlatformdesktop
FrostwireFrostwire Version6.5.0 Updatebuild236 SwPlatformdesktop
FrostwireFrostwire Version6.5.1 Updatebuild238 SwPlatformdesktop
FrostwireFrostwire Version6.5.2 Updatebuild239 SwPlatformdesktop
FrostwireFrostwire Version6.5.3 Updatebuild240 SwPlatformdesktop
FrostwireFrostwire Version6.5.4 Updatebuild241 SwPlatformdesktop
FrostwireFrostwire Version6.5.5 Updatebuild242 SwPlatformdesktop
FrostwireFrostwire Version6.5.5 Updatebuild243 SwPlatformdesktop
FrostwireFrostwire Version6.5.8 Updatebuild244 SwPlatformdesktop
FrostwireFrostwire Version6.5.8 Updatebuild245 SwPlatformdesktop
FrostwireFrostwire Version6.5.9 Updatebuild246 SwPlatformdesktop
FrostwireFrostwire Version6.6.0 Updatebuild248 SwPlatformdesktop
FrostwireFrostwire Version6.6.1 Updatebuild249 SwPlatformdesktop
FrostwireFrostwire Version6.6.2 Updatebuild250 SwPlatformdesktop
FrostwireFrostwire Version6.6.2 Updatebuild251 SwPlatformdesktop
FrostwireFrostwire Version6.6.3 Updatebuild252 SwPlatformdesktop
FrostwireFrostwire Version6.6.3 Updatebuild253 SwPlatformdesktop
FrostwireFrostwire Version6.6.4 Updatebuild256 SwPlatformdesktop
FrostwireFrostwire Version6.6.5 Updatebuild257 SwPlatformdesktop
FrostwireFrostwire Version6.6.6 Updatebuild258 SwPlatformdesktop
FrostwireFrostwire Version6.6.7 Updatebuild529 SwPlatformdesktop
FrostwireFrostwire Version6.6.8 Updatebuild260 SwPlatformdesktop
FrostwireFrostwire Version6.7.0 Updatebuild261 SwPlatformdesktop
FrostwireFrostwire Version6.7.0 Updatebuild262 SwPlatformdesktop
FrostwireFrostwire Version6.7.0 Updatebuild264 SwPlatformdesktop
FrostwireFrostwire Version6.7.0 Updatebuild265hotfix SwPlatformdesktop
FrostwireFrostwire Version6.7.1 Updatebuild266 SwPlatformdesktop
FrostwireFrostwire Version6.7.1 Updatebuild267 SwPlatformdesktop
FrostwireFrostwire Version6.7.1 Updatebuild268 SwPlatformdesktop
FrostwireFrostwire Version6.7.2 Updatebuild269 SwPlatformdesktop
FrostwireFrostwire Version6.7.2 Updatebuild270 SwPlatformdesktop
FrostwireFrostwire Version6.7.3 Updatebuild271 SwPlatformdesktop
FrostwireFrostwire Version6.7.4 Updatebuild272 SwPlatformdesktop
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.449
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.