VDB
CVE-2016-9928
CVE-2016-9928
PUBLISHED
CVSS 7.400000095367432 HIGH
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
EPSS 4.51% · 90.9th percentile
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
4.51%
90.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | mcabber | 0, 0.10.2-1, 0.10.2-1build1 |
Timeline
- Feb 10, 2017 PoC Published
- Feb 6, 2020 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2016-9928 third-party-advisory
- https://bitbucket.org/McKael/mcabber-crew/commits/6e1ead98930d7dd0a520ad17c720ae4908429033/raw third-party-advisory
- http://www.openwall.com/lists/oss-security/2016/12/09/5 third-party-advisory
- https://ubuntu.com/security/notices/USN-4506-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-9928 third-party-advisory