5.9
CVE-2019-10251
- EPSS 0.16%
- Veröffentlicht 28.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:44
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Office files (related to libpicsel), which allows MITM attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ucweb ≫ Uc Browser SwPlatformandroid Version <= 2019-03-26
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.369 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.