Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2011-1754
Disclosure Date: June 21, 2011 (last updated October 04, 2023)
jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown
CVE-2011-1757
Disclosure Date: June 21, 2011 (last updated October 04, 2023)
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown
CVE-2011-1755
Disclosure Date: June 21, 2011 (last updated February 03, 2024)
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown
CVE-2010-0305
Disclosure Date: February 03, 2010 (last updated October 04, 2023)
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload.
0
Attacker Value
Unknown
CVE-2009-0934
Disclosure Date: March 18, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.
0
Attacker Value
Unknown
CVE-2007-0903
Disclosure Date: February 13, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2006-2221
Disclosure Date: May 05, 2006 (last updated October 04, 2023)
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this vulnerability is present in other products that use this installer.
0
Attacker Value
Unknown
CVE-2006-1329
Disclosure Date: March 21, 2006 (last updated February 22, 2025)
The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".
0
Attacker Value
Unknown
CVE-2004-1378
Disclosure Date: September 21, 2004 (last updated February 22, 2025)
The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections.
0