Skip to main content

Vendor/product archive

ignite_realtime / openfire CVEs

Beta · best-effort

6 CVEs tagged to ignite_realtime / openfire0 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2009-0496

Published Feb 10, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1728

Published Apr 11, 2008

ConnectionManagerImpl.java in Ignite Realtime Openfire 3.4.5 allows remote authenticated users to cause a denial of service (daemon outage) by triggering large outgoing queues wit…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2975

Published Jun 1, 2007

The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allows remote attackers to gain pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7233

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.6.0, and possibly other versions before 3.5.3, allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4876

Published Dec 31, 2005

Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.2.2, and possibly other versions before 2.3.0 Beta 2,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4877

Published Dec 31, 2005

Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.3.0 Beta 2 allows remote attackers to inject arbitrar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1