process-one records
8 published records for vendor process-one.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-310 Cryptographic Issues2
- CWE-399 Resource Management Errors2
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2007-0903No exploit | Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.process-one · ejabberd | Critical10.0 | — | 1.9% | Feb 13, 2007 |
21Monitor | CVE-2010-0305No exploit | ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (akaprocess-one · ejabberd · CWE-20 | Medium5.0 | — | 3.1% | Feb 3, 2010 |
21Monitor | CVE-2011-1753No exploit | expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity process-one · ejabberd · CWE-399 | Medium5.0 | — | 2.1% | Jun 20, 2011 |
20Monitor | CVE-2014-8760No exploit | ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connectionprocess-one · ejabberd · CWE-310 | Medium5.0 | — | 1.3% | Oct 24, 2014 |
17Monitor | CVE-2011-4320No exploit | The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (iprocess-one · ejabberd · CWE-399 | Medium4.0 | — | 2.1% | Feb 17, 2012 |
17Monitor | CVE-2009-0934No exploit | Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknownprocess-one · ejabberd · CWE-79 | Medium4.3 | — | 1.6% | Mar 17, 2009 |
17Monitor | CVE-2013-6169No exploit | The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sprocess-one · ejabberd · CWE-310 | Medium4.3 | — | 1.6% | Oct 17, 2013 |
8Monitor | CVE-2006-2221No exploit | A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earbitrock · install builder | Low2.1 | — | 0.4% | May 5, 2006 |
- CVE-2007-090341Plan
Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%process-one · ejabberdFeb 13, 2007
- CVE-2010-030521Monitor
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka
MediumCVSS 5.0No exploitEPSS 3%process-one · ejabberdFeb 3, 2010
- CVE-2011-175321Monitor
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity
MediumCVSS 5.0No exploitEPSS 2%process-one · ejabberdJun 20, 2011
- CVE-2014-876020Monitor
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connection
MediumCVSS 5.0No exploitEPSS 1%process-one · ejabberdOct 24, 2014
- CVE-2011-432017Monitor
The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (i
MediumCVSS 4.0No exploitEPSS 2%process-one · ejabberdFeb 17, 2012
- CVE-2009-093417Monitor
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown
MediumCVSS 4.3No exploitEPSS 2%process-one · ejabberdMar 17, 2009
- CVE-2013-616917Monitor
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain s
MediumCVSS 4.3No exploitEPSS 2%process-one · ejabberdOct 17, 2013
- CVE-2006-22218Monitor
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and ear
LowCVSS 2.1No exploitEPSS 0%bitrock · install builderMay 5, 2006