FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.9.9-build246"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.9-build247"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.7-build263"
},
{
"introduced": "0"
},
{
"last_affected": "6.1.6-build166"
},
{
"introduced": "0"
},
{
"last_affected": "6.1.6-build167"
},
{
"introduced": "0"
},
{
"last_affected": "6.1.7-build168"
},
{
"introduced": "0"
},
{
"last_affected": "6.1.8-build169"
},
{
"introduced": "0"
},
{
"last_affected": "6.1.9-build172"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-build173"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-build174"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.1-build175"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.2-build176"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.3-build177"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.3-build178"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.4-build179"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.0-build180"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.0-build181"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.0-build182"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.0-build183"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.0-build184"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.0-build185"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.1-build186"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.2-build187"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.2-build188"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.3-build189"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.3-build190"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.3-build193"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.3-build255"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.4-build193"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.4-build194"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.5-build195"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.5-build197"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.5-build198"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.6-build201"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.6-build202"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.7-build203"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.7-build204"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.7-build205"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.7-build206"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.0-build207"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.0-build208"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.1-build209"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.1-build210"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.2-build212"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.3-build214"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.4-build215"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.5-build218"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.5-build219"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.5-build220"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.5-build221"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.5-build222"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.6-build223"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.6-build227"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.7-build228"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.7-build229"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.8-build230"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.8-build232"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.8-build233"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.8-build234"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.9-build235"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.0-build236"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.1-build238"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.2-build239"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.3-build240"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.4-build241"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.5-build242"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.5-build243"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.8-build244"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.8-build245"
},
{
"introduced": "0"
},
{
"last_affected": "6.5.9-build246"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.0-build248"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.1-build249"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.2-build250"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.2-build251"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.3-build252"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.3-build253"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.4-build256"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.5-build257"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.6-build258"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.7-build529"
},
{
"introduced": "0"
},
{
"last_affected": "6.6.8-build260"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.0-build261"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.0-build262"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.0-build264"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.0-build265hotfix"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.1-build266"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.1-build267"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.1-build268"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.2-build269"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.2-build270"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.3-build271"
},
{
"introduced": "0"
},
{
"last_affected": "6.7.4-build272"
}
]
}