Igniterealtime Smack vulnerabilities
3 known vulnerabilities affecting igniterealtime/smack.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2014-0364P4MEDIUMCVSS 5.0fixed in 4.0.02014-04-30
CVE-2014-0364 [MEDIUM] CWE-345 CVE-2014-0364: The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
nvd
CVE-2016-10027P4MEDIUMCVSS 5.9fixed in 4.1.92017-01-12
CVE-2016-10027 [MEDIUM] CWE-362 CVE-2016-10027: Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
nvd
CVE-2014-0363P4MEDIUMCVSS 5.8fixed in 4.0.02014-04-30
CVE-2014-0363 [MEDIUM] CWE-295 CVE-2014-0363: The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not ver
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.
nvd