Search CVE reports


Toggle filters

11 – 20 of 23 results


CVE-2021-32917

Low priority
Vulnerable

An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody Not affected Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2020-8086

Medium priority
Vulnerable

The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username...

1 affected package

prosody-modules

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody-modules Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-10847

Low priority

Some fixes available 2 of 3

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to...

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2017-18265

Medium priority

Some fixes available 1 of 2

Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The...

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-0756

Medium priority

Some fixes available 2 of 7

The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream...

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody Not affected
Show less packages

CVE-2016-1232

Medium priority

Some fixes available 3 of 4

The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody
Show less packages

CVE-2016-1231

Medium priority

Some fixes available 3 of 4

Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody
Show less packages

CVE-2014-2745

Medium priority
Ignored

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack,...

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody Not affected
Show less packages

CVE-2014-2744

Medium priority
Ignored

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of...

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody Not affected
Show less packages

CVE-2014-2750

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2744, CVE-2014-2745. Reason: This candidate is a duplicate of CVE-2014-2744 and/or CVE-2014-2745. Notes: All CVE users should reference CVE-2014-2744...

1 affected package

prosody

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prosody
Show less packages