Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Jabberd2
HIGH 7.8
CVE-2017-18225
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by …
Fix: after 2.6.1
Fix from $1,950
2018-03-12
Jabberd2
MEDIUM 5.5
CVE-2017-18226
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill a…
Fix: after 2.6.1
Fix from $1,600
2018-03-12
Jabberd2
CRITICAL 9.8
CVE-2017-10807
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enable…
Fix: after 2.6.0
Fix from $2,300
2017-07-04
Jabberd2
MEDIUM 6.5
CVE-2015-2058
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated us…
Fix: after 2.3.2
Fix from $1,600
2015-08-12