Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.
{ "urgency": "medium" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-0753.json"