Known vulnerabilities in Openfire - page 2
Vendor:
Ignite Realtime
Software:
Openfire
Software CPE:
cpe:2.3:a:ignite_realtime:openfire:*:*:*:*:*:*:*:*
Website:
https://igniterealtime.org/
Total vulnerabilities:
25
Public exploits:
4
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
5.1.1
5.1.0
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.9.2
4.9.1
4.9.0
4.8.3
4.8.2
4.8.1
4.8.0
4.7.5
4.6.8
4.7.4
4.7.3
4.7.2
4.7.1
4.7.0
4.5.6
4.6.7
4.6.6
4.5.5
4.6.5
4.6.4
4.6.3
4.6.2
4.6.1
4.6.0
3.6.0a
3.2.4
3.2.3
3.2.2
3.2.1
3.2.0
3.1.1
3.1.0
3.0.1
3.0.0
2.6.2
2.6.1
2.6.0
4.5.4
4.5.3
4.5.2
4.5.1
4.5.0
4.4.4
4.4.3
4
1
4.4.2
2
3
4.4.1
4.4.0
4.3.2
4.3.1
4.3.0
4.2.4
4.2.3
4.2.2
4.2.1
4.2.0
4.1.6
4.1.5
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0.
4.0.0
3.10.3
3.10.2
3.10.1
3.10.0
3.9.3
3.9.2
3.9.1
3.9.0
3.8.2
3.8.1
3.8.0
3.7.1
3.7.0.
3.7.0
3.6.4
3.6.3
3.6.2
3.6.1
3.6.0
3.5.2
3.5.1
3.5.0
3.4.5
3.4.4
3.4.3
3.4.2
3.4.1
3.4.0
3.3.3
3.3.2
3.3.1
3.3.0
Vulnerabilities (25)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU21741 - Improper input validation CVE-2014-2741 |
CWE-20 | Medium | 3.9.2 | 12.10.2019 |
SB2014041101 |
||
| #VU21740 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2015-6972 |
CWE-79 | Low | 3.10.3 | 12.10.2019 |
SB2015100508 SB2016122302 SB2016123104 |
||
| #VU21739 - Cross-Site Request Forgery (CSRF) CVE-2015-6973 |
CWE-352 | Medium | 3.10.3 | 12.10.2019 |
SB2015100508 SB2016122302 SB2016123104 |
||
| #VU21738 - Improper Authorization CVE-2015-7707 |
CWE-285 | Medium | 3.10.3 | 12.10.2019 |
SB2015100508 SB2016122302 SB2016123104 |
||
| #VU21737 - Improper Certificate Validation CVE-2014-3451 |
CWE-295 | Low | 3, 3.10.0 | 12.10.2019 |
SB2017081807 |
Showing elements 21 - 40 out of 25