Show filters
87 Total Results
Displaying 61-70 of 87
Sort by:
Attacker Value
Unknown

CVE-2010-2528

Disclosure Date: July 30, 2010 (last updated October 04, 2023)
The clientautoresp function in family_icbm.c in the oscar protocol plugin in libpurple in Pidgin before 2.7.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via an X-Status message that lacks the expected end tag for a (1) desc or (2) title element.
0
Attacker Value
Unknown

CVE-2010-1624

Disclosure Date: May 14, 2010 (last updated October 04, 2023)
The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message.
0
Attacker Value
Unknown

CVE-2010-0423

Disclosure Date: February 24, 2010 (last updated October 04, 2023)
gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.
0
Attacker Value
Unknown

CVE-2010-0420

Disclosure Date: February 24, 2010 (last updated October 04, 2023)
libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing <br> sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.
0
Attacker Value
Unknown

CVE-2010-0277

Disclosure Date: January 09, 2010 (last updated October 04, 2023)
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
0
Attacker Value
Unknown

CVE-2010-0013

Disclosure Date: January 09, 2010 (last updated January 27, 2024)
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
Attacker Value
Unknown

CVE-2009-3615

Disclosure Date: October 20, 2009 (last updated October 04, 2023)
The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.
0
Attacker Value
Unknown

CVE-2009-3085

Disclosure Date: September 08, 2009 (last updated October 04, 2023)
The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.
0
Attacker Value
Unknown

CVE-2009-2703

Disclosure Date: September 08, 2009 (last updated October 04, 2023)
libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.
0
Attacker Value
Unknown

CVE-2009-3083

Disclosure Date: September 08, 2009 (last updated October 04, 2023)
The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.
0