Lightwitch maintains a narrowly scoped product portfolio centered on the Metronome application, with observed disclosures clustering around improper input validation weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lightwitch over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2744HIGH plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remo | Apr 11, 2014 | 7.8 | 21 | NO | NO |
CVE-2014-2743HIGH plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denia | Apr 11, 2014 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lightwitch.
Media articles that mention a CVE ID that affects a product developed by Lightwitch — matched by CVE ID, not by vendor name.