Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-43506 An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused b… Prosody 0.12.6 / 13.0.5+ Fix from $1,9502026-05-01 HIGH 7.5 CVE-2026-43507 An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused b… Prosody 0.12.6 / 13.0.5+ Fix from $1,9502026-05-01 MEDIUM 6.5 CVE-2026-43504 An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles … Prosody 0.12.6 / 13.0.5+ Fix from $1,6002026-05-01 MEDIUM 6.5 CVE-2026-43505 An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles … Prosody 0.12.6 / 13.0.5+ Fix from $1,6002026-05-01 HIGH 7.5 CVE-2022-0217 It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML da… Prosody 0.11.12+ Fix from $1,9502022-08-26 HIGH 7.5 CVE-2021-37601 muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned ent… Prosody after 0.11.9 Fix from $1,9502021-07-30 HIGH 8.8 CVE-2018-10847 prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user… Prosody 0.9.14+ Fix from $1,9502018-07-30 MEDIUM 5.3 CVE-2016-0756 The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, w… Prosody after 0.9.9 Fix from $1,6002016-01-29 HIGH 7.8 CVE-2014-2745 Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service… Prosody after 0.9.3 Fix from $1,9502014-04-11 MEDIUM 5.0 CVE-2011-2532 The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via… Prosody Patch available Fix from $1,6002011-06-22 MEDIUM 5.0 CVE-2011-2205 Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory a… Prosody after 0.8.0 Fix from $1,6002011-06-22