Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Unknown
CVE-2013-6482
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2) OIM XML response, or (3) Content-Length header.
0
Attacker Value
Unknown
CVE-2013-6481
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (crash) via a Yahoo! P2P message with a crafted length field, which triggers a buffer over-read.
0
Attacker Value
Unknown
CVE-2013-6489
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Integer signedness error in the MXit functionality in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (segmentation fault) via a crafted emoticon value, which triggers an integer overflow and a buffer overflow.
0
Attacker Value
Unknown
CVE-2013-6490
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header, which triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2013-6479
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denial of service (application crash) via a crafted response.
0
Attacker Value
Unknown
CVE-2013-6485
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid chunk-size field in chunked transfer-coding data.
0
Attacker Value
Unknown
CVE-2014-0020
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.
0
Attacker Value
Unknown
CVE-2013-6484
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash) by triggering a socket read error.
0
Attacker Value
Unknown
CVE-2013-6477
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a crafted timestamp value in an XMPP message.
0
Attacker Value
Unknown
CVE-2013-6486
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: URL that is improperly handled during construction of an explorer.exe command. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3185.
0