Jabberd2

Jabberd2

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 12.03.2018 04:29:00
  • Last modified 21.11.2024 03:19:36

The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this acc...

  • EPSS 0.03%
  • Published 12.03.2018 04:29:00
  • Last modified 21.11.2024 03:19:37

The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root scrip...

  • EPSS 1.57%
  • Published 04.07.2017 15:29:00
  • Last modified 20.04.2025 01:37:25

JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.

  • EPSS 0.48%
  • Published 12.08.2015 14:59:08
  • Last modified 12.04.2025 10:46:40

c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.

Exploit
  • EPSS 2.93%
  • Published 25.08.2012 16:55:00
  • Last modified 11.04.2025 00:51:21

s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.

  • EPSS 8.46%
  • Published 21.06.2011 02:52:43
  • Last modified 11.04.2025 00:51:21

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity reference...