Filtered by vendor Brad Fitzpatrick
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-2206 | 1 Brad Fitzpatrick | 1 Djabberd | 2024-11-21 | 5.5 MEDIUM | N/A |
XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757. | |||||
CVE-2011-1757 | 1 Brad Fitzpatrick | 1 Djabberd | 2024-11-21 | 5.0 MEDIUM | N/A |
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. |