process-one kayıtları
process-one üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %87,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-310 Cryptographic Issues2
- CWE-399 Resource Management Errors2
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2007-0903İstismar yok | Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.process-one · ejabberd | Kritik10,0 | — | %1,9 | 13 Şub 2007 |
21İzleyin | CVE-2010-0305İstismar yok | ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (akaprocess-one · ejabberd · CWE-20 | Orta5,0 | — | %3,1 | 3 Şub 2010 |
21İzleyin | CVE-2011-1753İstismar yok | expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity process-one · ejabberd · CWE-399 | Orta5,0 | — | %2,1 | 20 Haz 2011 |
20İzleyin | CVE-2014-8760İstismar yok | ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connectionprocess-one · ejabberd · CWE-310 | Orta5,0 | — | %1,3 | 24 Eki 2014 |
17İzleyin | CVE-2011-4320İstismar yok | The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (iprocess-one · ejabberd · CWE-399 | Orta4,0 | — | %2,1 | 17 Şub 2012 |
17İzleyin | CVE-2009-0934İstismar yok | Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknownprocess-one · ejabberd · CWE-79 | Orta4,3 | — | %1,6 | 17 Mar 2009 |
17İzleyin | CVE-2013-6169İstismar yok | The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sprocess-one · ejabberd · CWE-310 | Orta4,3 | — | %1,6 | 17 Eki 2013 |
8İzleyin | CVE-2006-2221İstismar yok | A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earbitrock · install builder | Düşük2,1 | — | %0,4 | 5 May 2006 |
- CVE-2007-090341Planlayın
Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.
KritikCVSS 10,0İstismar yokEPSS %2process-one · ejabberd13 Şub 2007
- CVE-2010-030521İzleyin
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka
OrtaCVSS 5,0İstismar yokEPSS %3process-one · ejabberd3 Şub 2010
- CVE-2011-175321İzleyin
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity
OrtaCVSS 5,0İstismar yokEPSS %2process-one · ejabberd20 Haz 2011
- CVE-2014-876020İzleyin
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connection
OrtaCVSS 5,0İstismar yokEPSS %1process-one · ejabberd24 Eki 2014
- CVE-2011-432017İzleyin
The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (i
OrtaCVSS 4,0İstismar yokEPSS %2process-one · ejabberd17 Şub 2012
- CVE-2009-093417İzleyin
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown
OrtaCVSS 4,3İstismar yokEPSS %2process-one · ejabberd17 Mar 2009
- CVE-2013-616917İzleyin
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain s
OrtaCVSS 4,3İstismar yokEPSS %2process-one · ejabberd17 Eki 2013
- CVE-2006-22218İzleyin
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and ear
DüşükCVSS 2,1İstismar yokEPSS %0bitrock · install builder5 May 2006