Show filters
78 Total Results
Displaying 51-60 of 78
Sort by:
Attacker Value
Unknown
CVE-2014-8760
Disclosure Date: October 25, 2014 (last updated October 05, 2023)
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
0
Attacker Value
Unknown
CVE-2014-0666
Disclosure Date: January 16, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056.
0
Attacker Value
Unknown
CVE-2013-6169
Disclosure Date: October 17, 2013 (last updated October 05, 2023)
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack.
0
Attacker Value
Unknown
CVE-2013-1228
Disclosure Date: September 06, 2013 (last updated October 05, 2023)
Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280.
0
Attacker Value
Unknown
CVE-2013-3393
Disclosure Date: June 26, 2013 (last updated October 05, 2023)
The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60706 and CSCue21117.
0
Attacker Value
Unknown
CVE-2013-1187
Disclosure Date: April 16, 2013 (last updated October 05, 2023)
The Connection Manager in Cisco Jabber Extensible Communications Platform (aka Jabber XCP) does not properly validate login data, which allows remote attackers to cause a denial of service (service crash) by sending a series of malformed login packets, aka Bug ID CSCts76762.
0
Attacker Value
Unknown
CVE-2013-1161
Disclosure Date: March 26, 2013 (last updated October 05, 2023)
The XML parser in the Cisco Jabber IM application for Android allows remote authenticated users to cause a denial of service (blocked connection) by leveraging an entry on a Buddy list and sending a crafted XMPP presence update message, aka Bug ID CSCue38383.
0
Attacker Value
Unknown
CVE-2012-3935
Disclosure Date: September 12, 2012 (last updated October 05, 2023)
Cisco Unified Presence (CUP) before 8.6(3) and Jabber Extensible Communications Platform (aka Jabber XCP) before 5.3 allow remote attackers to cause a denial of service (process crash) via a crafted XMPP stream header, aka Bug ID CSCtu32832.
0
Attacker Value
Unknown
CVE-2012-3525
Disclosure Date: August 25, 2012 (last updated October 04, 2023)
s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.
0
Attacker Value
Unknown
CVE-2011-4320
Disclosure Date: February 18, 2012 (last updated October 04, 2023)
The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.
0