Vulnerabilities > Jabber

DATE CVE VULNERABILITY TITLE RISK
2009-08-11 CVE-2008-6937 Code Injection vulnerability in Jabber Exodus 0.10
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936.
network
low complexity
jabber CWE-94
critical
10.0
2009-08-11 CVE-2008-6936 Code Injection vulnerability in Jabber Exodus 0.10
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935.
network
jabber CWE-94
critical
9.3
2009-03-03 CVE-2008-6393 Numeric Errors vulnerability in Psi-Im PSI
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.
network
low complexity
psi-im jabber CWE-189
critical
10.0