Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000825

Опубликовано: 20 дек. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 10

Описание

FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Freecol file.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

not-affected

0.11.6+dfsg2-3
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

0.11.6+dfsg2-3
esm-apps/jammy

not-affected

0.11.6+dfsg2-3
esm-apps/noble

not-affected

0.11.6+dfsg2-3
esm-apps/xenial

needs-triage

Показывать по

EPSS

Процентиль: 48%
0.00245
Низкий

7.5 High

CVSS2

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
nvd
около 7 лет назад

FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Freecol file.

CVSS3: 10
debian
около 7 лет назад

FreeCol version <= nightly-2018-08-22 contains a XML External Entity ( ...

CVSS3: 10
github
больше 3 лет назад

FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Freecol file.

EPSS

Процентиль: 48%
0.00245
Низкий

7.5 High

CVSS2

10 Critical

CVSS3