Vulnerabilities (CVE)

Filtered by vendor Jabberd2 Subscribe
Filtered by product Jabberd2
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-2058 1 Jabberd2 1 Jabberd2 2016-11-30 6.5 MEDIUM N/A
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.
CVE-2012-3525 2 Jabber2, Jabberd2 2 Jabberd2, Jabberd2 2013-06-15 5.8 MEDIUM N/A
s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.