Show filters
89 Total Results
Displaying 81-89 of 89
Sort by:
Attacker Value
Unknown
CVE-2009-1376
Disclosure Date: May 26, 2009 (last updated November 08, 2023)
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
0
Attacker Value
Unknown
CVE-2008-3532
Disclosure Date: August 08, 2008 (last updated October 04, 2023)
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
0
Attacker Value
Unknown
CVE-2008-2927
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.
0
Attacker Value
Unknown
CVE-2008-2956
Disclosure Date: July 01, 2008 (last updated November 08, 2023)
Memory leak in Pidgin 2.0.0, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via malformed XML documents. NOTE: this issue has been disputed by the upstream vendor, who states: "I was never able to identify a scenario under which a problem occurred and the original reporter wasn't able to supply any sort of reproduction details."
0
Attacker Value
Unknown
CVE-2008-2955
Disclosure Date: July 01, 2008 (last updated October 04, 2023)
Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_slplink_process_msg function.
0
Attacker Value
Unknown
CVE-2008-2957
Disclosure Date: July 01, 2008 (last updated October 04, 2023)
The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.
0
Attacker Value
Unknown
CVE-2007-4999
Disclosure Date: October 29, 2007 (last updated October 04, 2023)
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
0
Attacker Value
Unknown
CVE-2007-4996
Disclosure Date: October 01, 2007 (last updated October 04, 2023)
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
0
Attacker Value
Unknown
CVE-2007-3841
Disclosure Date: July 17, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to execute certain commands via unspecified vectors, aka ZD-00000035. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.
0