Show filters
78 Total Results
Displaying 61-70 of 78
Sort by:
Attacker Value
Unknown

CVE-2011-3287

Disclosure Date: October 06, 2011 (last updated October 04, 2023)
Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x through 5.4.x before 5.4.0.27581 and 5.8.x before 5.8.1.27561 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containing a large number of nested entity references, aka Bug ID CSCtq78106, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown

CVE-2011-2206

Disclosure Date: June 22, 2011 (last updated October 04, 2023)
XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757.
0
Attacker Value
Unknown

CVE-2011-1753

Disclosure Date: June 21, 2011 (last updated October 04, 2023)
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown

CVE-2011-1754

Disclosure Date: June 21, 2011 (last updated October 04, 2023)
jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown

CVE-2011-1757

Disclosure Date: June 21, 2011 (last updated October 04, 2023)
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown

CVE-2011-1755

Disclosure Date: June 21, 2011 (last updated February 03, 2024)
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Attacker Value
Unknown

CVE-2010-0305

Disclosure Date: February 03, 2010 (last updated October 04, 2023)
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload.
0
Attacker Value
Unknown

CVE-2009-0934

Disclosure Date: March 18, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.
0
Attacker Value
Unknown

CVE-2008-4952

Disclosure Date: November 05, 2008 (last updated October 04, 2023)
emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary file.
0
Attacker Value
Unknown

CVE-2007-0903

Disclosure Date: February 13, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.
0