Search: "pidgin"

93 CVEs found

CVE-2009-3084
5.0 MEDIUM

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial...

Published: 2009-09-08
Products: 38
Vendors:
pidgin
CVE-2009-3085
5.0 MEDIUM

The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial o...

Published: 2009-09-08
Products: 37
Vendors:
pidgin
CVE-2009-3615
5.0 MEDIUM

The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ ...

Published: 2009-10-20
Products: 46
Vendors:
pidgin adium

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/...

Published: 2010-01-09
Products: 10
Vendors:
redhat pidgin adium suse fedoraproject +1 more
CVE-2010-0277
5.0 MEDIUM

slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or...

Published: 2010-01-09
Products: 30
Vendors:
pidgin adium
CVE-2010-0420
4.3 MEDIUM

libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing <br> sequences, which allows remote attackers to cause a denial...

Published: 2010-02-24
Products: 29
Vendors:
pidgin
CVE-2010-0423
5.0 MEDIUM

gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.

Published: 2010-02-24
Products: 29
Vendors:
pidgin
CVE-2010-1624
5.0 MEDIUM

The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and appli...

Published: 2010-05-14
Products: 5
Vendors:
canonical pidgin
CVE-2010-2528
4.0 MEDIUM

The clientautoresp function in family_icbm.c in the oscar protocol plugin in libpurple in Pidgin before 2.7.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference a...

Published: 2010-07-30
Products: 32
Vendors:
pidgin
CVE-2010-3088
5.1 MEDIUM

The notify function in pidgin-knotify.c in the pidgin-knotify plugin 0.2.1 and earlier for Pidgin allows remote attackers to execute arbitrary commands via shell metacharacters in a message.

Published: 2010-10-08
Products: 5
Vendors:
pidgin jianping_yu
CVE-2010-3711
4.0 MEDIUM

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer de...

Published: 2010-10-28
Products: 34
Vendors:
pidgin
CVE-2010-4528
4.0 MEDIUM

directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application...

Published: 2011-01-07
Products: 42
Vendors:
pidgin
CVE-2011-1091
4.0 MEDIUM

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) ...

Published: 2011-03-14
Products: 17
Vendors:
pidgin
CVE-2011-2943
4.3 MEDIUM

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted re...

Published: 2011-08-29
Products: 46
Vendors:
pidgin
CVE-2011-3184
4.3 MEDIUM

The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a...

Published: 2011-08-29
Products: 44
Vendors:
pidgin

gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.

Published: 2011-08-29
Products: 45
Vendors:
pidgin microsoft
CVE-2011-3594
4.3 MEDIUM

The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (cra...

Published: 2011-11-04
Products: 48
Vendors:
pidgin
CVE-2011-4602
5.0 MEDIUM

The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of s...

Published: 2011-12-17
Products: 45
Vendors:
pidgin
CVE-2011-4603
5.0 MEDIUM

The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attacker...

Published: 2011-12-17
Products: 45
Vendors:
pidgin
CVE-2011-4601
5.0 MEDIUM

family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of se...

Published: 2011-12-25
Products: 45
Vendors:
pidgin