Back to Database
Status published
Medium
CVE-2010-0305
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause...
Vulnerability Description
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-0305
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2010/01/29/1
- http://secunia.com/advisories/38337
- http://www.openwall.com/lists/oss-security/2010/01/29/5
- http://www.osvdb.org/62066
- http://www.vupen.com/english/advisories/2010/0894
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56025
- http://www.debian.org/security/2010/dsa-2033
- https://support.process-one.net/browse/EJAB-1173
- http://www.securityfocus.com/bid/38003
- http://secunia.com/advisories/39423
More from process-one
View All →CVE-2014-8760
ejabberd before 2.1.13 does not enforce the starttls_required setting when...
Medium
5
CVE-2013-6169
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2...
Medium
4.3
CVE-2011-4320
The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows...
Medium
4
CVE-2011-1753
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and...
Medium
5
CVE-2009-0934
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote...
Medium
4.3
Affected Vendor
process-one
View all reports →Affected Software
ejabberd
Vulnerable Versions:
0, 0.9, 0.9.1, 0.9.8, 1.0.0, 1.1.0, 1.1.1, 1.1.1.0, 1.1.1.1, 1.1.2, 1.1.3, 1.1.14, 2.0.0, 2.0.1_2, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.1.0, 2.1.1
Timeline
Official Publish:
February 3rd, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.