Skip to main content

Vendor archive

process-one CVEs

Beta · best-effort

8 CVEs tagged to vendor process-one1 Critical, 0 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2014-8760

Published Oct 25, 2014

ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6169

Published Oct 17, 2013

The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4320

Published Feb 18, 2012

The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publi…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1753

Published Jun 21, 2011

expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0305

Published Feb 3, 2010

ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0934

Published Mar 18, 2009

Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0903

Published Feb 13, 2007

Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-2221

Published May 5, 2006

A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allow…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1