Search: "pidgin"

93 CVEs found

CVE-2011-4939
6.4 MEDIUM

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickn...

Published: 2012-03-15
Products: 46
Vendors:
pidgin
CVE-2012-1178
5.0 MEDIUM

The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial of service (application crash) via an OIM message t...

Published: 2012-03-15
Products: 46
Vendors:
pidgin

Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbit...

Published: 2012-05-23
Products: 2
Vendors:
pidgin cypherpunks

proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (applicati...

Published: 2012-07-03
Products: 48
Vendors:
pidgin
CVE-2012-2318
5.0 MEDIUM

msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placi...

Published: 2012-07-03
Products: 48
Vendors:
pidgin

Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.

Published: 2012-07-07
Products: 49
Vendors:
pidgin

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or o...

Published: 2012-08-08
Products: 45
Vendors:
pidgin
CVE-2013-0271
5.0 MEDIUM

The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote attackers to create or overwrite files via a crafted (1) mxit or (2) mxit/imagestrips pathname.

Published: 2013-02-16
Products: 51
Vendors:
pidgin
CVE-2013-0272
6.8 MEDIUM

Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code via a long HTTP header.

Published: 2013-02-16
Products: 51
Vendors:
pidgin
CVE-2013-0273
5.0 MEDIUM

sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service (application crash) ...

Published: 2013-02-16
Products: 51
Vendors:
pidgin

upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging acc...

Published: 2013-02-16
Products: 51
Vendors:
pidgin
CVE-2012-6152
5.0 MEDIUM

The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application crash) via crafted byte s...

Published: 2014-02-06
Products: 53
Vendors:
pidgin
CVE-2013-6477
5.0 MEDIUM

Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a crafted timestamp value in an XMPP message.

Published: 2014-02-06
Products: 53
Vendors:
pidgin
CVE-2013-6478
4.3 MEDIUM

gtkimhtml.c in Pidgin before 2.10.8 does not properly interact with underlying library support for wide Pango layouts, which allows user-assisted remote attackers to cause a denial of service (applica...

Published: 2014-02-06
Products: 53
Vendors:
pidgin
CVE-2013-6479
5.0 MEDIUM

util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denia...

Published: 2014-02-06
Products: 53
Vendors:
pidgin
CVE-2013-6483
6.4 MEDIUM

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remot...

Published: 2014-02-06
Products: 53
Vendors:
pidgin
CVE-2013-6484
5.0 MEDIUM

The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash) by triggering a sock...

Published: 2014-02-06
Products: 53
Vendors:
pidgin
CVE-2013-6485
5.0 MEDIUM

Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid chun...

Published: 2014-02-06
Products: 53
Vendors:
pidgin

gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: URL that is improperly handled during construction of...

Published: 2014-02-06
Products: 53
Vendors:
pidgin
CVE-2014-0020
5.0 MEDIUM

The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.

Published: 2014-02-06
Products: 53
Vendors:
pidgin