CVE Database
/

CVE-2016-9928

Back to search

CVE-2016-9928

Published: Feb 6, 2020

Modified: Aug 6, 2024

PUBLISHED

Description

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

VendorProductVersions

MCabber

MCabber

affected
before 1.0.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now