Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pidgin MEDIUM 5.5
CVE-2019-25544

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long userna…

No fix yet
Fix from $1,600 2026-03-21
Pidgin MEDIUM 5.5
CVE-2012-1257

Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

Mitigation only
Fix from $1,600 2019-11-20
Mxit HIGH 8.8
CVE-2016-2379

The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging know…

Mitigation only
Fix from $1,950 2017-03-29
Pidgin MEDIUM 6.4
CVE-2014-3697

Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to wri…

Fix: after 2.10.9
Fix from $1,600 2014-10-29
Pidgin MEDIUM 5.0
CVE-2014-3695

markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via…

Fix: after 2.10.9
Fix from $1,600 2014-10-29
Pidgin MEDIUM 5.0
CVE-2014-3696

nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (applicati…

Fix: after 2.10.9
Fix from $1,600 2014-10-29
Pidgin MEDIUM 5.0
CVE-2014-3698

The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sen…

Fix: after 2.10.9
Fix from $1,600 2014-10-29
Pidgin HIGH 10.0
CVE-2013-6490EPSS 15%

The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header,…

Fix: after 2.10.7
Fix from $1,950 2014-02-06
Pidgin HIGH 7.5
CVE-2013-6487EPSS 8%

Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have an unspeci…

Fix: after 2.10.7
Fix from $1,950 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6481

libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (crash) via a Yahoo! P2P message wit…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6482

Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2)…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6489EPSS 6%

Integer signedness error in the MXit functionality in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (segmentation fault) …

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2014-0020

The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of …

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin HIGH 9.3
CVE-2013-6486

gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: UR…

Fix: after 2.10.7
Fix from $1,950 2014-02-06
Pidgin MEDIUM 6.4
CVE-2013-6483

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with …

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2012-6152

The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denia…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6477

Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6479

util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6484

The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write op…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6485

Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibl…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 6.8
CVE-2013-0272

Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code via a long…

Fix: after 2.10.6
Fix from $1,600 2013-02-16
Pidgin MEDIUM 5.0
CVE-2013-0271

The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote attackers to create or overwrite files via a crafted (1) mxit or (2)…

Fix: after 2.10.6
Fix from $1,600 2013-02-16
Pidgin MEDIUM 5.0
CVE-2013-0273

sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote server…

Fix: after 2.10.6
Fix from $1,600 2013-02-16
Pidgin HIGH 7.5
CVE-2012-3374EPSS 6%

Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a …

Fix: after 2.10.4
Fix from $1,950 2012-07-07
Pidgin MEDIUM 5.0
CVE-2012-2318

msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cau…

Fix: after 2.10.3
Fix from $1,600 2012-07-03
Pidgin MEDIUM 6.4
CVE-2011-4939

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer der…

Fix: after 2.10.1
Fix from $1,600 2012-03-15
Pidgin MEDIUM 5.0
CVE-2012-1178

The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial …

Fix: after 2.10.1
Fix from $1,600 2012-03-15
Pidgin MEDIUM 5.0
CVE-2011-4601

family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, wh…

Fix: after 2.10.0
Fix from $1,600 2011-12-25
Pidgin MEDIUM 5.0
CVE-2011-4603

The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 valid…

Fix: after 2.10.0
Fix from $1,600 2011-12-17
Pidgin MEDIUM 5.0
CVE-2011-4602

The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, w…

Fix: after 2.10.0
Fix from $1,600 2011-12-17