Prosody kayıtları
prosody üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-399 Resource Management Errors3
- CWE-20 Improper Input Validation2
- CWE-863 Incorrect Authorization2
- CWE-295 Improper Certificate Validation1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-8086İstismar yok | The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_prosody · mod auth ldap · CWE-863 | Kritik9,8 | — | %1,6 | 28 Oca 2020 |
35İzleyin | CVE-2018-10847İstismar yok | prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.prosody · prosody · CWE-592 | Yüksek8,8 | — | %1,7 | 30 Tem 2018 |
32İzleyin | CVE-2022-0217İstismar yok | It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsprosody · prosody · CWE-776 | Yüksek7,5 | — | %5,4 | 26 Ağu 2022 |
32İzleyin | CVE-2014-2744İstismar yok | plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a sessilightwitch · metronome · CWE-20 | Yüksek7,8 | — | %3,3 | 10 Nis 2014 |
32İzleyin | CVE-2014-2745İstismar yok | Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial oprosody · prosody · CWE-264 | Yüksek7,8 | — | %3,1 | 10 Nis 2014 |
31İzleyin | CVE-2021-37601İstismar yok | muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and bprosody · prosody | Yüksek7,5 | — | %2,3 | 30 Tem 2021 |
31İzleyin | CVE-2021-32920İstismar yok | Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.prosody · prosody | Yüksek7,5 | — | %2,3 | 13 May 2021 |
31İzleyin | CVE-2016-1232İstismar yok | The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback prosody · prosody | Yüksek7,5 | — | %2,2 | 12 Oca 2016 |
31İzleyin | CVE-2021-32918İstismar yok | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-400 | Yüksek7,5 | — | %2,1 | 13 May 2021 |
31İzleyin | CVE-2017-18265İstismar yok | Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain vprosody · prosody | Yüksek7,5 | — | %1,7 | 9 May 2018 |
30İzleyin | CVE-2021-32919İstismar yok | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-295 | Yüksek7,5 | — | %1,4 | 13 May 2021 |
30İzleyin | CVE-2026-43507İstismar yok | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.prosody · prosody · CWE-770 | Yüksek7,5 | — | %0,6 | 1 May 2026 |
30İzleyin | CVE-2026-43506İstismar yok | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.prosody · prosody · CWE-401 | Yüksek7,5 | — | %0,5 | 1 May 2026 |
26İzleyin | CVE-2026-43504İstismar yok | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.prosody · prosody · CWE-863 | Orta6,5 | — | %0,3 | 1 May 2026 |
26İzleyin | CVE-2026-43505İstismar yok | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.prosody · prosody · CWE-420 | Orta6,5 | — | %0,3 | 1 May 2026 |
24İzleyin | CVE-2016-1231İstismar yok | Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to prosody · prosody · CWE-22 | Orta5,9 | — | %2,9 | 12 Oca 2016 |
23İzleyin | CVE-2021-32921İstismar yok | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-362 | Orta5,9 | — | %1,6 | 13 May 2021 |
22İzleyin | CVE-2021-32917İstismar yok | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-862 | Orta5,3 | — | %2,2 | 13 May 2021 |
22İzleyin | CVE-2016-0756İstismar yok | The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialbacprosody · prosody · CWE-20 | Orta5,3 | — | %2,1 | 29 Oca 2016 |
21İzleyin | CVE-2011-2205İstismar yok | Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service prosody · prosody · CWE-399 | Orta5,0 | — | %2,1 | 22 Haz 2011 |
20İzleyin | CVE-2011-2532İstismar yok | The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite prosody · prosody · CWE-399 | Orta5,0 | — | %1,4 | 22 Haz 2011 |
17İzleyin | CVE-2011-2531İstismar yok | Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remoprosody · prosody · CWE-399 | Orta4,3 | — | %1,4 | 22 Haz 2011 |
- CVE-2020-808639İzleyin
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_
KritikCVSS 9,8İstismar yokEPSS %2prosody · mod auth ldap28 Oca 2020
- CVE-2018-1084735İzleyin
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.
YüksekCVSS 8,8İstismar yokEPSS %2prosody · prosody30 Tem 2018
- CVE-2022-021732İzleyin
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in pars
YüksekCVSS 7,5İstismar yokEPSS %5prosody · prosody26 Ağu 2022
- CVE-2014-274432İzleyin
plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a sessi
YüksekCVSS 7,8İstismar yokEPSS %3lightwitch · metronome10 Nis 2014
- CVE-2014-274532İzleyin
Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial o
YüksekCVSS 7,8İstismar yokEPSS %3prosody · prosody10 Nis 2014
- CVE-2021-3760131İzleyin
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and b
YüksekCVSS 7,5İstismar yokEPSS %2prosody · prosody30 Tem 2021
- CVE-2021-3292031İzleyin
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
YüksekCVSS 7,5İstismar yokEPSS %2prosody · prosody13 May 2021
- CVE-2016-123231İzleyin
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback
YüksekCVSS 7,5İstismar yokEPSS %2prosody · prosody12 Oca 2016
- CVE-2021-3291831İzleyin
An issue was discovered in Prosody before 0.11.9.
YüksekCVSS 7,5İstismar yokEPSS %2prosody · prosody13 May 2021
- CVE-2017-1826531İzleyin
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain v
YüksekCVSS 7,5İstismar yokEPSS %2prosody · prosody9 May 2018
- CVE-2021-3291930İzleyin
An issue was discovered in Prosody before 0.11.9.
YüksekCVSS 7,5İstismar yokEPSS %1prosody · prosody13 May 2021
- CVE-2026-4350730İzleyin
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.
YüksekCVSS 7,5İstismar yokEPSS %1prosody · prosody1 May 2026
- CVE-2026-4350630İzleyin
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.
YüksekCVSS 7,5İstismar yokEPSS %0prosody · prosody1 May 2026
- CVE-2026-4350426İzleyin
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.
OrtaCVSS 6,5İstismar yokEPSS %0prosody · prosody1 May 2026
- CVE-2026-4350526İzleyin
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.
OrtaCVSS 6,5İstismar yokEPSS %0prosody · prosody1 May 2026
- CVE-2016-123124İzleyin
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to
OrtaCVSS 5,9İstismar yokEPSS %3prosody · prosody12 Oca 2016
- CVE-2021-3292123İzleyin
An issue was discovered in Prosody before 0.11.9.
OrtaCVSS 5,9İstismar yokEPSS %2prosody · prosody13 May 2021
- CVE-2021-3291722İzleyin
An issue was discovered in Prosody before 0.11.9.
OrtaCVSS 5,3İstismar yokEPSS %2prosody · prosody13 May 2021
- CVE-2016-075622İzleyin
The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialbac
OrtaCVSS 5,3İstismar yokEPSS %2prosody · prosody29 Oca 2016
- CVE-2011-220521İzleyin
Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service
OrtaCVSS 5,0İstismar yokEPSS %2prosody · prosody22 Haz 2011
- CVE-2011-253220İzleyin
The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite
OrtaCVSS 5,0İstismar yokEPSS %1prosody · prosody22 Haz 2011
- CVE-2011-253117İzleyin
Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remo
OrtaCVSS 4,3İstismar yokEPSS %1prosody · prosody22 Haz 2011