CVE-2022-26491
- EPSS 0.49%
- Veröffentlicht 02.06.2022 14:15:40
- Zuletzt bearbeitet 21.11.2024 06:54:02
An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the or...
CVE-2012-1257
- EPSS 0.23%
- Veröffentlicht 20.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:36:45
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
CVE-2016-1000030
- EPSS 0.78%
- Veröffentlicht 05.09.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 02:42:51
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exp...
CVE-2017-2640
- EPSS 1%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:53
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.
CVE-2016-4323
- EPSS 2%
- Veröffentlicht 06.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can prov...
CVE-2016-2380
- EPSS 0.53%
- Veröffentlicht 06.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get c...
CVE-2016-2378
- EPSS 3.31%
- Veröffentlicht 06.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially result in a buffer overflow, potentially resulting in memory corruption. A malicious server or an unfilte...
CVE-2016-2377
- EPSS 3.31%
- Veröffentlicht 06.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can send a negative content-lengt...
CVE-2016-2374
- EPSS 2.78%
- Veröffentlicht 06.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disclosure and code execution.
CVE-2016-2365
- EPSS 3.25%
- Veröffentlicht 06.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A malicious server or an attacker who intercepts the netw...