Search: "pidgin"

93 CVEs found

Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to execute certain commands via unspecified vectors, aka ZD-00000...

Published: 2007-07-17
Products: 1
Vendors:
pidgin
CVE-2007-4996
4.3 MEDIUM

libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via...

Published: 2007-10-01
Products: 1
Vendors:
pidgin
CVE-2007-5379
5.0 MEDIUM

Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash...

Published: 2007-10-19
Products: 1
Vendors:
david_hansson
CVE-2007-4999
4.3 MEDIUM

libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML...

Published: 2007-10-29
Products: 3
Vendors:
pidgin
CVE-2008-2955
4.3 MEDIUM

Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_...

Published: 2008-07-01
Products: 1
Vendors:
pidgin
CVE-2008-2956
5.0 MEDIUM

Memory leak in Pidgin 2.0.0, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via malformed XML documents. NOTE: this issue has been disputed by t...

Published: 2008-07-01
Products: 1
Vendors:
pidgin
CVE-2008-2957
6.4 MEDIUM

The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a...

Published: 2008-07-01
Products: 1
Vendors:
pidgin
CVE-2008-2927
6.8 MEDIUM

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2....

Published: 2008-07-07
Products: 25
Vendors:
pidgin adium
CVE-2008-3532
6.8 MEDIUM

The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed serv...

Published: 2008-08-08
Products: 1
Vendors:
pidgin

Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file tran...

Published: 2009-05-26
Products: 21
Vendors:
pidgin
CVE-2009-1374
5.0 MEDIUM

Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet.

Published: 2009-05-26
Products: 21
Vendors:
pidgin
CVE-2009-1375
5.0 MEDIUM

The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers to cause a denial of service (memory corruption an...

Published: 2009-05-26
Products: 21
Vendors:
pidgin

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly...

Published: 2009-05-26
Products: 9
Vendors:
pidgin
CVE-2009-1889
5.0 MEDIUM

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (applicatio...

Published: 2009-07-01
Products: 26
Vendors:
pidgin

Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messe...

Published: 2009-08-03
Products: 7
Vendors:
aol pidgin mozilla gnome
CVE-2009-2694
10.0 HIGH

The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute a...

Published: 2009-08-21
Products: 29
Vendors:
pidgin adium
CVE-2009-3025
4.3 MEDIUM

Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.

Published: 2009-08-31
Products: 1
Vendors:
pidgin
CVE-2009-3026
5.0 MEDIUM

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP ...

Published: 2009-08-31
Products: 1
Vendors:
pidgin
CVE-2009-2703
5.0 MEDIUM

libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) vi...

Published: 2009-09-08
Products: 37
Vendors:
pidgin
CVE-2009-3083
5.0 MEDIUM

The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer derefer...

Published: 2009-09-08
Products: 37
Vendors:
pidgin