Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
229 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.48% | — | Cisco Jabber | 6/9/2013 | 16/6/2026 | Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280. | |
| Modificada | Media (5) | 1.2% | — | Cisco JabberCisco Virtualization Experience Media Engine | 26/6/2013 | 16/6/2026 | The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60706 and CSCue21117. | |
| Modificada | Media (5) | 1.2% | — | Cisco Jabber Extensible Communications Platform | 16/4/2013 | 16/6/2026 | The Connection Manager in Cisco Jabber Extensible Communications Platform (aka Jabber XCP) does not properly validate login data, which allows remote attackers to cause a denial of service (service crash) by sending a series of malformed login packets, aka Bug ID CSCts76762. | |
| Modificada | Media (6.3) | 0.93% | — | Cisco Jabber IM | 26/3/2013 | 16/6/2026 | The XML parser in the Cisco Jabber IM application for Android allows remote authenticated users to cause a denial of service (blocked connection) by leveraging an entry on a Buddy list and sending a crafted XMPP presence update message, aka Bug ID CSCue38383. | |
| Modificada | Alta (7.8) | 2.8% | — | Cisco Unified PresenceCisco Jabber Extensible Communications Platform | 12/9/2012 | 16/6/2026 | Cisco Unified Presence (CUP) before 8.6(3) and Jabber Extensible Communications Platform (aka Jabber XCP) before 5.3 allow remote attackers to cause a denial of service (process crash) via a crafted XMPP stream header, aka Bug ID CSCtu32832. | |
| Modificada | Media (5.8) | 1.7% | — | Jabber2 Jabberd2Jabberd2 | 25/8/2012 | 16/6/2026 | s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response. | |
| Modificada | Media (6.8) | 0.69% | — | Phpjabbers Vacation Rental Script | 14/8/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in PHPJabbers Vacation Rental Script allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a create action in the AdminUsers module to index.php. | |
| Modificada | Media (4) | 2.0% | — | Process-one Ejabberd | 18/2/2012 | 16/6/2026 | The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute. | |
| Modificada | Alta (7.8) | 1.2% | — | Cisco Jabber Extensible Communications Platform | 6/10/2011 | 16/6/2026 | Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x through 5.4.x before 5.4.0.27581 and 5.8.x before 5.8.1.27561 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML… | |
| Modificada | Media (5.5) | 1.3% | — | Brad Fitzpatrick Djabberd | 22/6/2011 | 16/6/2026 | XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than… | |
| Modificada | Media (5) | 1.1% | — | Brad Fitzpatrick Djabberd | 21/6/2011 | 16/6/2026 | DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | |
| Modificada | Alta (7.5) | 3.7% | — | Jabberd2Fedoraproject FedoraApple MAC OS XApple MAC OS X Server | 21/6/2011 | 16/6/2026 | jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | |
| Modificada | Media (5) | 2.3% | — | Jabberd14 | 21/6/2011 | 16/6/2026 | jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | |
| Modificada | Media (5) | 2.1% | — | Process-one EjabberdProcess-one Exmpp | 21/6/2011 | 16/6/2026 | expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity… | |
| Modificada | Media (5) | 3.1% | — | Process-one Ejabberd | 3/2/2010 | 16/6/2026 | ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload. | |
| Modificada | Alta (10) | 3.2% | 💥 Exploit | Jabber Exodus | 11/8/2009 | 16/6/2026 | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936. NOTE: the provenance of this information is… | |
| Modificada | Alta (9.3) | 3.1% | 💥 Exploit | Jabber Exodus | 11/8/2009 | 16/6/2026 | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935. | |
| Modificada | Media (4.3) | 1.6% | — | Process-one Ejabberd | 18/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs. | |
| Modificada | Media (6.9) | 0.37% | — | Emacs-jabber | 5/11/2008 | 16/6/2026 | emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary file. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | PHP Jabbers Post Comment | 23/10/2008 | 16/6/2026 | PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged." | |
| Modificada | Alta (10) | 1.9% | — | Process-one Ejabberd | 13/2/2007 | 16/6/2026 | Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors. | |
| Modificada | Baja (2.1) | 0.37% | — | Bitrock Install BuilderProcess-one Ejabberd | 5/5/2006 | 16/6/2026 | A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this… | |
| Modificada | Media (5) | 2.9% | — | Jabberstudio Jabberd | 21/3/2006 | 16/6/2026 | The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza". | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Jabber Software Foundation Jabber Server | 10/1/2005 | 16/6/2026 | Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long username. | |
| Modificada | Media (5) | 1.4% | — | Jabberstudio Jabber Gadu-gadu Transport | 31/12/2004 | 16/6/2026 | The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors. |