Debian Mcabber vulnerabilities
4 known vulnerabilities affecting debian/mcabber.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW2
Vulnerabilities
Page 1 of 1
CVE-2017-5604MEDIUMCVSS 5.9fixed in mcabber 1.0.4-1.1 (bookworm)2017
CVE-2017-5604 [MEDIUM] CVE-2017-5604: mcabber - An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clie...
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for mcabber 1.0.0 - 1.0.4.
Scope: local
bookworm: resolved (fixed in 1.0.4-1.1)
bullseye: resolved (
debian
CVE-2016-9928HIGHCVSS 7.4fixed in mcabber 0.10.2-1.1 (bookworm)2016
CVE-2016-9928 [HIGH] CVE-2016-9928: mcabber - MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote a...
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
Scope: local
bookworm: resolved (fixed in 0.10.2-1.1)
bullseye: resolved (fixed in 0.10.2-1.1)
forky: resolv
debian
CVE-2009-3720LOWCVSS 5.0fixed in audacity 1.3.2-1 (bookworm)2009
CVE-2009-3720 [MEDIUM] CVE-2009-3720: audacity - The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as ...
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Scope: local
bookwor
debian
CVE-2009-3560LOWCVSS 5.0fixed in audacity 1.3.2-1 (bookworm)2009
CVE-2009-3560 [MEDIUM] CVE-2009-3560: audacity - The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in ...
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-20
debian