CVE-2019-9673
Published Jun 5, 2019
Last updated 5 years ago
Overview
- Description
- Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-19
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:freenetproject:freenet:0.7.5:1472:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "535383D8-84F9-4490-8F44-E9FE4CDCDEEC" }, { "criteria": "cpe:2.3:a:freenetproject:freenet:0.7.5:1473:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A663B3E-1092-461D-9940-E3557D6C0E8D" }, { "criteria": "cpe:2.3:a:freenetproject:freenet:0.7.5:1475:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DAA39DE8-E8E6-4255-B7DA-3B7992D6ADF6" }, { "criteria": "cpe:2.3:a:freenetproject:freenet:0.7.5:1476:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D970AD0-2BAB-4D98-BD4D-EAB5B79E907A" }, { "criteria": "cpe:2.3:a:freenetproject:freenet:0.7.5:1477:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA6736AD-C650-4C38-9AD3-F74808239F5E" }, { "criteria": "cpe:2.3:a:freenetproject:freenet:0.7.5:1479:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1BACF2C6-9A91-4B2D-89DA-0C4D11F70440" }, { "criteria": "cpe:2.3:a:freenetproject:freenet:0.7.5:1480:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF68D226-EF4A-4288-B3AE-112E0916BBFA" }, { "criteria": "cpe:2.3:a:freenetproject:freenet:0.7.5:1483:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C78C21A8-9F7E-48DA-ADD8-FA804CBFB075" } ], "operator": "OR" } ] } ]