Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
jabberd嵌入XML实体拒绝服务漏洞
Vulnerability Description
jabberd是一款基于XMMP(一种以XML为基础的开放式实时通信协议)的即时聊天服务器。 jabberd 2.2.14之前版本没有正确解析某些XML输入。远程攻击者可以借助嵌入的XML实体导致拒绝服务(CPU和内存消耗)。
CVSS Information
N/A
Vulnerability Type
N/A