VulnerabilityModified
CVE-2004-0013
jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).
MEDIUM 5.0EPSS 1.80%
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- jabber software foundation/jabber server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/10559
- http://www.debian.org/security/2004/dsa-414Patch, Vendor Advisory
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005Patch, Vendor Advisory
- http://www.osvdb.org/3345
- http://www.securityfocus.com/bid/9376Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14158
- http://secunia.com/advisories/10559
- http://www.debian.org/security/2004/dsa-414Patch, Vendor Advisory
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005Patch, Vendor Advisory
- http://www.osvdb.org/3345
- http://www.securityfocus.com/bid/9376Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14158
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.