5

CVE-2014-3698

The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sensitive information from process memory via a crafted XMPP message.

Data is provided by the National Vulnerability Database (NVD)
PidginPidgin Version <= 2.10.9
PidginPidgin Version2.10.0
PidginPidgin Version2.10.1
PidginPidgin Version2.10.2
PidginPidgin Version2.10.3
PidginPidgin Version2.10.4
PidginPidgin Version2.10.5
PidginPidgin Version2.10.6
PidginPidgin Version2.10.7
PidginPidgin Version2.10.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.33% 0.781
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.