Skip to content

CVE-2014-0364

The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0043 (0.4%)
Percentile: 62.9%
EPSS: 2026-05-06

Affects

igniterealtime:smack

Technical description

The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.

Published: 4/30/2014, 10:49:04 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam