Записи process-one
8 опубликованных записей вендора process-one.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 87,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-310 Cryptographic Issues2
- CWE-399 Resource Management Errors2
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2007-0903Эксплойта нет | Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.process-one · ejabberd | Критическая10,0 | — | 1,9 % | 13 февр. 2007 г. |
21Наблюдать | CVE-2010-0305Эксплойта нет | ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (akaprocess-one · ejabberd · CWE-20 | Средняя5,0 | — | 3,1 % | 3 февр. 2010 г. |
21Наблюдать | CVE-2011-1753Эксплойта нет | expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity process-one · ejabberd · CWE-399 | Средняя5,0 | — | 2,1 % | 20 июн. 2011 г. |
20Наблюдать | CVE-2014-8760Эксплойта нет | ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connectionprocess-one · ejabberd · CWE-310 | Средняя5,0 | — | 1,3 % | 24 окт. 2014 г. |
17Наблюдать | CVE-2011-4320Эксплойта нет | The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (iprocess-one · ejabberd · CWE-399 | Средняя4,0 | — | 2,1 % | 17 февр. 2012 г. |
17Наблюдать | CVE-2009-0934Эксплойта нет | Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknownprocess-one · ejabberd · CWE-79 | Средняя4,3 | — | 1,6 % | 17 мар. 2009 г. |
17Наблюдать | CVE-2013-6169Эксплойта нет | The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sprocess-one · ejabberd · CWE-310 | Средняя4,3 | — | 1,6 % | 17 окт. 2013 г. |
8Наблюдать | CVE-2006-2221Эксплойта нет | A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earbitrock · install builder | Низкая2,1 | — | 0,4 % | 5 мая 2006 г. |
- CVE-2007-090341В плане
Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %process-one · ejabberd13 февр. 2007 г.
- CVE-2010-030521Наблюдать
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka
СредняяCVSS 5,0Эксплойта нетEPSS 3 %process-one · ejabberd3 февр. 2010 г.
- CVE-2011-175321Наблюдать
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity
СредняяCVSS 5,0Эксплойта нетEPSS 2 %process-one · ejabberd20 июн. 2011 г.
- CVE-2014-876020Наблюдать
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connection
СредняяCVSS 5,0Эксплойта нетEPSS 1 %process-one · ejabberd24 окт. 2014 г.
- CVE-2011-432017Наблюдать
The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (i
СредняяCVSS 4,0Эксплойта нетEPSS 2 %process-one · ejabberd17 февр. 2012 г.
- CVE-2009-093417Наблюдать
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown
СредняяCVSS 4,3Эксплойта нетEPSS 2 %process-one · ejabberd17 мар. 2009 г.
- CVE-2013-616917Наблюдать
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain s
СредняяCVSS 4,3Эксплойта нетEPSS 2 %process-one · ejabberd17 окт. 2013 г.
- CVE-2006-22218Наблюдать
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and ear
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %bitrock · install builder5 мая 2006 г.