Filtered by vendor Gajim
Subscribe
Search
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2016-10376 | 1 Gajim | 1 Gajim | 2017-11-06 | 3.5 LOW | 4.5 MEDIUM |
| Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions. | |||||
| CVE-2015-8688 | 1 Gajim | 1 Gajim | 2016-12-07 | 5.8 MEDIUM | 5.4 MEDIUM |
| Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza. | |||||
