Записи Prosody
22 опубликованных записей вендора prosody.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-399 Resource Management Errors3
- CWE-20 Improper Input Validation2
- CWE-863 Incorrect Authorization2
- CWE-295 Improper Certificate Validation1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-8086Эксплойта нет | The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_prosody · mod auth ldap · CWE-863 | Критическая9,8 | — | 1,6 % | 28 янв. 2020 г. |
35Наблюдать | CVE-2018-10847Эксплойта нет | prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.prosody · prosody · CWE-592 | Высокая8,8 | — | 1,7 % | 30 июл. 2018 г. |
32Наблюдать | CVE-2022-0217Эксплойта нет | It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsprosody · prosody · CWE-776 | Высокая7,5 | — | 5,4 % | 26 авг. 2022 г. |
32Наблюдать | CVE-2014-2744Эксплойта нет | plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a sessilightwitch · metronome · CWE-20 | Высокая7,8 | — | 3,3 % | 10 апр. 2014 г. |
32Наблюдать | CVE-2014-2745Эксплойта нет | Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial oprosody · prosody · CWE-264 | Высокая7,8 | — | 3,1 % | 10 апр. 2014 г. |
31Наблюдать | CVE-2021-37601Эксплойта нет | muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and bprosody · prosody | Высокая7,5 | — | 2,3 % | 30 июл. 2021 г. |
31Наблюдать | CVE-2021-32920Эксплойта нет | Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.prosody · prosody | Высокая7,5 | — | 2,3 % | 13 мая 2021 г. |
31Наблюдать | CVE-2016-1232Эксплойта нет | The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback prosody · prosody | Высокая7,5 | — | 2,2 % | 12 янв. 2016 г. |
31Наблюдать | CVE-2021-32918Эксплойта нет | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-400 | Высокая7,5 | — | 2,1 % | 13 мая 2021 г. |
31Наблюдать | CVE-2017-18265Эксплойта нет | Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain vprosody · prosody | Высокая7,5 | — | 1,7 % | 9 мая 2018 г. |
30Наблюдать | CVE-2021-32919Эксплойта нет | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-295 | Высокая7,5 | — | 1,4 % | 13 мая 2021 г. |
30Наблюдать | CVE-2026-43507Эксплойта нет | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.prosody · prosody · CWE-770 | Высокая7,5 | — | 0,6 % | 1 мая 2026 г. |
30Наблюдать | CVE-2026-43506Эксплойта нет | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.prosody · prosody · CWE-401 | Высокая7,5 | — | 0,5 % | 1 мая 2026 г. |
26Наблюдать | CVE-2026-43504Эксплойта нет | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.prosody · prosody · CWE-863 | Средняя6,5 | — | 0,3 % | 1 мая 2026 г. |
26Наблюдать | CVE-2026-43505Эксплойта нет | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.prosody · prosody · CWE-420 | Средняя6,5 | — | 0,3 % | 1 мая 2026 г. |
24Наблюдать | CVE-2016-1231Эксплойта нет | Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to prosody · prosody · CWE-22 | Средняя5,9 | — | 2,9 % | 12 янв. 2016 г. |
23Наблюдать | CVE-2021-32921Эксплойта нет | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-362 | Средняя5,9 | — | 1,6 % | 13 мая 2021 г. |
22Наблюдать | CVE-2021-32917Эксплойта нет | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-862 | Средняя5,3 | — | 2,2 % | 13 мая 2021 г. |
22Наблюдать | CVE-2016-0756Эксплойта нет | The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialbacprosody · prosody · CWE-20 | Средняя5,3 | — | 2,1 % | 29 янв. 2016 г. |
21Наблюдать | CVE-2011-2205Эксплойта нет | Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service prosody · prosody · CWE-399 | Средняя5,0 | — | 2,1 % | 22 июн. 2011 г. |
20Наблюдать | CVE-2011-2532Эксплойта нет | The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite prosody · prosody · CWE-399 | Средняя5,0 | — | 1,4 % | 22 июн. 2011 г. |
17Наблюдать | CVE-2011-2531Эксплойта нет | Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remoprosody · prosody · CWE-399 | Средняя4,3 | — | 1,4 % | 22 июн. 2011 г. |
- CVE-2020-808639Наблюдать
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %prosody · mod auth ldap28 янв. 2020 г.
- CVE-2018-1084735Наблюдать
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %prosody · prosody30 июл. 2018 г.
- CVE-2022-021732Наблюдать
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in pars
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %prosody · prosody26 авг. 2022 г.
- CVE-2014-274432Наблюдать
plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a sessi
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %lightwitch · metronome10 апр. 2014 г.
- CVE-2014-274532Наблюдать
Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial o
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %prosody · prosody10 апр. 2014 г.
- CVE-2021-3760131Наблюдать
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and b
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %prosody · prosody30 июл. 2021 г.
- CVE-2021-3292031Наблюдать
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %prosody · prosody13 мая 2021 г.
- CVE-2016-123231Наблюдать
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %prosody · prosody12 янв. 2016 г.
- CVE-2021-3291831Наблюдать
An issue was discovered in Prosody before 0.11.9.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %prosody · prosody13 мая 2021 г.
- CVE-2017-1826531Наблюдать
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain v
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %prosody · prosody9 мая 2018 г.
- CVE-2021-3291930Наблюдать
An issue was discovered in Prosody before 0.11.9.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %prosody · prosody13 мая 2021 г.
- CVE-2026-4350730Наблюдать
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %prosody · prosody1 мая 2026 г.
- CVE-2026-4350630Наблюдать
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %prosody · prosody1 мая 2026 г.
- CVE-2026-4350426Наблюдать
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %prosody · prosody1 мая 2026 г.
- CVE-2026-4350526Наблюдать
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %prosody · prosody1 мая 2026 г.
- CVE-2016-123124Наблюдать
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to
СредняяCVSS 5,9Эксплойта нетEPSS 3 %prosody · prosody12 янв. 2016 г.
- CVE-2021-3292123Наблюдать
An issue was discovered in Prosody before 0.11.9.
СредняяCVSS 5,9Эксплойта нетEPSS 2 %prosody · prosody13 мая 2021 г.
- CVE-2021-3291722Наблюдать
An issue was discovered in Prosody before 0.11.9.
СредняяCVSS 5,3Эксплойта нетEPSS 2 %prosody · prosody13 мая 2021 г.
- CVE-2016-075622Наблюдать
The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialbac
СредняяCVSS 5,3Эксплойта нетEPSS 2 %prosody · prosody29 янв. 2016 г.
- CVE-2011-220521Наблюдать
Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service
СредняяCVSS 5,0Эксплойта нетEPSS 2 %prosody · prosody22 июн. 2011 г.
- CVE-2011-253220Наблюдать
The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite
СредняяCVSS 5,0Эксплойта нетEPSS 1 %prosody · prosody22 июн. 2011 г.
- CVE-2011-253117Наблюдать
Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remo
СредняяCVSS 4,3Эксплойта нетEPSS 1 %prosody · prosody22 июн. 2011 г.