Vulnerabilities
Vulnerable Software
Prosody:  Security Vulnerabilities
The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonstrated by truncated data.
CVSS Score
5.0
EPSS Score
0.014
Published
2011-06-22
Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS Score
5.0
EPSS Score
0.021
Published
2011-06-22


Contact Us

Shodan ® - All rights reserved