Vulnerabilities
Vulnerable Software
Prosody:  >> Prosody  >> 0.4.0  Security Vulnerabilities
Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.
CVSS Score
7.8
EPSS Score
0.027
Published
2014-04-11
Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS Score
5.0
EPSS Score
0.016
Published
2011-06-22


Contact Us

Shodan ® - All rights reserved