VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Prosody
>
Prosody
> 0.9.13
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2022-08-26
CVE-2022-0217
XML Entity Expansion vulnerability in Prosody
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data.
network
low complexity
prosody
CWE-776
7.5
7.5
2021-05-13
CVE-2021-32917
Missing Authorization vulnerability in multiple products
An issue was discovered in Prosody before 0.11.9.
network
low complexity
prosody
debian
fedoraproject
CWE-862
5.3
5.3
2021-05-13
CVE-2021-32918
Resource Exhaustion vulnerability in multiple products
An issue was discovered in Prosody before 0.11.9.
network
low complexity
prosody
debian
fedoraproject
CWE-400
7.5
7.5
2021-05-13
CVE-2021-32920
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
network
low complexity
prosody
debian
fedoraproject
7.5
7.5
2021-05-13
CVE-2021-32921
Race Condition vulnerability in multiple products
An issue was discovered in Prosody before 0.11.9.
network
high complexity
prosody
fedoraproject
debian
CWE-362
5.9
5.9
2018-07-30
CVE-2018-10847
Improper Authentication vulnerability in Prosody
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.
network
low complexity
prosody
CWE-287
8.8
8.8
2018-05-09
CVE-2017-18265
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch.
network
low complexity
prosody
debian
7.5
7.5