CVE-2017-18225
- EPSS 0.04%
- Published 12.03.2018 04:29:00
- Last modified 21.11.2024 03:19:36
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this acc...
CVE-2017-18226
- EPSS 0.03%
- Published 12.03.2018 04:29:00
- Last modified 21.11.2024 03:19:37
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root scrip...
CVE-2017-10807
- EPSS 1.57%
- Published 04.07.2017 15:29:00
- Last modified 20.04.2025 01:37:25
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
CVE-2015-2058
- EPSS 0.48%
- Published 12.08.2015 14:59:08
- Last modified 12.04.2025 10:46:40
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.
CVE-2012-3525
- EPSS 2.93%
- Published 25.08.2012 16:55:00
- Last modified 11.04.2025 00:51:21
s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.
CVE-2011-1755
- EPSS 8.46%
- Published 21.06.2011 02:52:43
- Last modified 11.04.2025 00:51:21
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity reference...