Skip to main content

Vendor archive

pidgin CVEs

Beta · best-effort

91 CVEs tagged to vendor pidgin8 Critical, 13 High, 65 Medium, 5 Low, 0 Unrated.

CVE-2014-3695

Published Oct 29, 2014

markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an em…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-6490

Published Feb 6, 2014

The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header, which triggers a buffer overf…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6489

Published Feb 6, 2014

Integer signedness error in the MXit functionality in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (segmentation fault) via a crafted emoticon value,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6487

Published Feb 6, 2014

Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a large Conten…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6482

Published Feb 6, 2014

Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2) OIM XML response, or (3) Cont…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6481

Published Feb 6, 2014

libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (crash) via a Yahoo! P2P message with a crafted length field, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0020

Published Feb 6, 2014

The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6486

Published Feb 6, 2014

gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: URL that is improperly handled d…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6485

Published Feb 6, 2014

Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibly have unspecified other impac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6484

Published Feb 6, 2014

The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6483

Published Feb 6, 2014

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq reques…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6479

Published Feb 6, 2014

util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP ser…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6478

Published Feb 6, 2014

gtkimhtml.c in Pidgin before 2.10.8 does not properly interact with underlying library support for wide Pango layouts, which allows user-assisted remote attackers to cause a denia…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6477

Published Feb 6, 2014

Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a crafted timestamp value in an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6152

Published Feb 6, 2014

The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application cras…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0274

Published Feb 16, 2013

upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application cra…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0273

Published Feb 16, 2013

sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0272

Published Feb 16, 2013

Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code via a long HTTP header.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0271

Published Feb 16, 2013

The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote attackers to create or overwrite files via a crafted (1) mxit or (2) mxit/imagestrips pathname.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4922

Published Aug 8, 2012

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by rea…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3374

Published Jul 7, 2012

Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a mess…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2318

Published Jul 3, 2012

msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (applic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2214

Published Jul 3, 2012

proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2369

Published May 23, 2012

Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 91 CVEsPage 2 of 4