Dragos & IronNet Partner on Critical Infrastructure Security

Dragos & IronNet Partner on Critical Infrastructure Security
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2021-29623PUBLISHED: 2021-05-13

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying th...

CVE-2021-32917PUBLISHED: 2021-05-13

An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.

CVE-2021-32918PUBLISHED: 2021-05-13

An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.

CVE-2021-32919PUBLISHED: 2021-05-13

An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another serv...

CVE-2021-32920PUBLISHED: 2021-05-13

Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.




Support the originator by clicking the read the rest link below.