Skip to main content

Vendor archive

pidgin CVEs

Beta · best-effort

91 CVEs tagged to vendor pidgin8 Critical, 13 High, 65 Medium, 5 Low, 0 Unrated.

CVE-2012-1178

Published Mar 15, 2012

The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial of service (application crash)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4939

Published Mar 15, 2012

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4601

Published Dec 25, 2011

family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4603

Published Dec 17, 2011

The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4602

Published Dec 17, 2011

The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3594

Published Nov 4, 2011

The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a d…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3185

Published Aug 29, 2011

gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3184

Published Aug 29, 2011

The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2943

Published Aug 29, 2011

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which al…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1091

Published Mar 14, 2011

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference an…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4528

Published Jan 7, 2011

directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer derefe…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3711

Published Oct 28, 2010

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of ser…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3088

Published Oct 8, 2010

The notify function in pidgin-knotify.c in the pidgin-knotify plugin 0.2.1 and earlier for Pidgin allows remote attackers to execute arbitrary commands via shell metacharacters in…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2528

Published Jul 30, 2010

The clientautoresp function in family_icbm.c in the oscar protocol plugin in libpurple in Pidgin before 2.7.2 allows remote authenticated users to cause a denial of service (NULL…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1624

Published May 14, 2010

The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0423

Published Feb 24, 2010

gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0420

Published Feb 24, 2010

libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing <br> sequences, which allows remote attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0277

Published Jan 9, 2010

slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3615

Published Oct 20, 2009

The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-l…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3085

Published Sep 8, 2009

The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3084

Published Sep 8, 2009

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attack…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3083

Published Sep 8, 2009

The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2703

Published Sep 8, 2009

libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3026

Published Aug 31, 2009

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 91 CVEsPage 3 of 4