Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pidgin HIGH 9.3
CVE-2011-3185

gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.

Fix: after 2.9.0
Fix from $1,950 2011-08-29
Pidgin MEDIUM 5.0
CVE-2010-0423

gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smiley…

Fix: after 2.6.5
Fix from $1,600 2010-02-24
Libpurple MEDIUM 5.0
CVE-2009-2703

libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service …

Fix: after 2.6.1
Fix from $1,600 2009-09-08
Libpurple MEDIUM 5.0
CVE-2009-3083

The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers…

Fix: after 2.6.1
Fix from $1,600 2009-09-08
Pidgin MEDIUM 5.0
CVE-2009-3084

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin befo…

Fix: after 2.6.1
Fix from $1,600 2009-09-08
Libpurple MEDIUM 5.0
CVE-2009-3085

The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley…

Fix: after 2.6.1
Fix from $1,600 2009-09-08
Pidgin MEDIUM 5.0
CVE-2009-3026

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting t…

Patch available
Fix from $1,600 2009-08-31
Pidgin MEDIUM 5.0
CVE-2009-1889

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote…

Fix: after 2.5.7
Fix from $1,600 2009-07-01
Pidgin HIGH 9.3
CVE-2009-1376EPSS 13%

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libp…

Fix: after 2.5.5
Fix from $1,950 2009-05-26
Pidgin HIGH 7.1
CVE-2009-1373

Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary co…

Fix: after 2.5.5
Fix from $1,950 2009-05-26
Pidgin MEDIUM 5.0
CVE-2009-1374

Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application …

Fix: after 2.5.5
Fix from $1,600 2009-05-26
Pidgin MEDIUM 5.0
CVE-2009-1375

The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers…

Fix: after 2.5.5
Fix from $1,600 2009-05-26
Pidgin MEDIUM 6.8
CVE-2008-3532

The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepti…

Patch available
Fix from $1,600 2008-08-08
Pidgin MEDIUM 6.8
CVE-2008-2927

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libp…

Fix: after 2.4.2
Fix from $1,600 2008-07-07
Pidgin MEDIUM 6.4
CVE-2008-2957

The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a d…

Mitigation only
Fix from $1,600 2008-07-01
Pidgin MEDIUM 5.0
CVE-2008-2956

Memory leak in Pidgin 2.0.0, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via malformed XML…

Mitigation only
Fix from $1,600 2008-07-01
Pidgin HIGH 9.0
CVE-2007-3841

Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to execute cer…

No fix yet
Fix from $1,950 2007-07-17