Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10376

Опубликовано: 28 мая 2017
Источник: nvd
CVSS3: 4.5
CVSS2: 3.5
EPSS Низкий

Описание

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gajim:gajim:*:*:*:*:*:*:*:*
Версия до 0.16.7 (включая)

EPSS

Процентиль: 63%
0.01153
Низкий

4.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-310

Связанные уязвимости

CVSS3: 4.5
ubuntu
больше 9 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

CVSS3: 4.5
debian
больше 9 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote ...

suse-cvrf
около 9 лет назад

Security update for gajim

CVSS3: 4.5
github
больше 4 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

EPSS

Процентиль: 63%
0.01153
Низкий

4.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-310