CVE detail
CVE-2014-3697
Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to write to arbitrary files via a drive name in a tar archive of a smiley theme.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- Vulnerabilities Found in Pidgin Chat ClientSecurityWeek
The latest version of the popular instant messaging application Pidgin (2.10.10) addresses multiple vulnerabilities, including three reported by Cisco’s Talos security intelligence and research group.
newswww.securityweek.comNov 10, 2014, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-4323CVSS 3.7 · Low
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A…
- CVE-2010-0013CVSS 7.5 · High
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot do…
- CVE-2026-66397CVSS 8.6 · High
phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by…
- CVE-2026-66476CVSS 4.9 · Medium
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
- CVE-2026-66050CVSS 8.7 · High
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitra…
- CVE-2026-65436CVSS 6.8 · Medium
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.