Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown
CVE-2013-6483
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply.
0
Attacker Value
Unknown
CVE-2012-6152
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application crash) via crafted byte sequences.
0
Attacker Value
Unknown
CVE-2013-6478
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
gtkimhtml.c in Pidgin before 2.10.8 does not properly interact with underlying library support for wide Pango layouts, which allows user-assisted remote attackers to cause a denial of service (application crash) via a long URL that is examined with a tooltip.
0
Attacker Value
Unknown
CVE-2013-0273
Disclosure Date: February 16, 2013 (last updated October 05, 2023)
sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service (application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2013-0274
Disclosure Date: February 16, 2013 (last updated October 05, 2023)
upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.
0
Attacker Value
Unknown
CVE-2013-0272
Disclosure Date: February 16, 2013 (last updated October 05, 2023)
Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code via a long HTTP header.
0
Attacker Value
Unknown
CVE-2013-0271
Disclosure Date: February 16, 2013 (last updated October 05, 2023)
The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote attackers to create or overwrite files via a crafted (1) mxit or (2) mxit/imagestrips pathname.
0
Attacker Value
Unknown
CVE-2011-4922
Disclosure Date: August 08, 2012 (last updated October 04, 2023)
cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.
0
Attacker Value
Unknown
CVE-2012-3374
Disclosure Date: July 07, 2012 (last updated October 04, 2023)
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.
0
Attacker Value
Unknown
CVE-2012-2318
Disclosure Date: July 03, 2012 (last updated October 04, 2023)
msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message.
0