VYPR
High severity7.5NVD Advisory· Published Jun 21, 2011· Updated Apr 29, 2026

CVE-2011-1755

CVE-2011-1755

Description

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

Affected products

6
  • cpe:2.3:a:jabberd2:jabberd2:*:*:*:*:*:*:*:*
    Range: <2.2.14
  • cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Range: <10.6.8
  • cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*
    Range: <10.6.8
  • cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:14:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.