Process-one

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 8
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2014-8760

    ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.

    Last Modified: Apr 12, 2025
    Published: Oct 25, 2014

    CVE-2013-6169

    The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack.

    Last Modified: Apr 11, 2025
    Published: Oct 17, 2013

    CVE-2011-4320

    The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.

    Last Modified: Apr 11, 2025
    Published: Feb 18, 2012

    CVE-2011-1753

    expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Last Modified: Apr 11, 2025
    Published: Jun 21, 2011

    CVE-2010-0305

    ejabberd: Remote DoS via flood of client2server messages

    Last Modified: Apr 11, 2025
    Published: Jan 28, 2010
    Items Per Page
    Process-One Vulnerabilities & Security CVEs | CVE-DB