Show filters
49 Total Results
Displaying 21-30 of 49
Sort by:
Attacker Value
Unknown

CVE-2012-2318

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message.
0
Attacker Value
Unknown

CVE-2012-2214

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.
0
Attacker Value
Unknown

CVE-2011-4939

Disclosure Date: March 15, 2012 (last updated October 04, 2023)
The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.
0
Attacker Value
Unknown

CVE-2012-1178

Disclosure Date: March 15, 2012 (last updated October 04, 2023)
The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial of service (application crash) via an OIM message that lacks UTF-8 encoding.
0
Attacker Value
Unknown

CVE-2011-4601

Disclosure Date: December 25, 2011 (last updated October 04, 2023)
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.
0
Attacker Value
Unknown

CVE-2011-4603

Disclosure Date: December 17, 2011 (last updated October 04, 2023)
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
0
Attacker Value
Unknown

CVE-2011-4602

Disclosure Date: December 17, 2011 (last updated October 04, 2023)
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
0
Attacker Value
Unknown

CVE-2011-3594

Disclosure Date: November 04, 2011 (last updated October 04, 2023)
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.
0
Attacker Value
Unknown

CVE-2011-2943

Disclosure Date: August 29, 2011 (last updated October 04, 2023)
The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response.
0
Attacker Value
Unknown

CVE-2011-3184

Disclosure Date: August 29, 2011 (last updated October 04, 2023)
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.
0