- EPSS 1.17%
- Published 17.12.2011 03:54:46
- Last modified 11.04.2025 00:51:21
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash)...
- EPSS 1.46%
- Published 17.12.2011 03:54:45
- Last modified 11.04.2025 00:51:21
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
CVE-2011-3594
- EPSS 0.96%
- Published 04.11.2011 21:55:07
- Last modified 11.04.2025 00:51:21
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use o...
CVE-2011-3185
- EPSS 5.09%
- Published 29.08.2011 17:55:01
- Last modified 11.04.2025 00:51:21
gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.
CVE-2011-3184
- EPSS 2.69%
- Published 29.08.2011 17:55:01
- Last modified 11.04.2025 00:51:21
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and ap...
CVE-2011-2943
- EPSS 3.96%
- Published 29.08.2011 17:55:00
- Last modified 11.04.2025 00:51:21
The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL ...
- EPSS 1.49%
- Published 14.03.2011 19:55:02
- Last modified 11.04.2025 00:51:21
libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allo...
- EPSS 2.69%
- Published 07.01.2011 12:00:49
- Last modified 11.04.2025 00:51:21
directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a short p2pv2 packet in a DirectConnec...
- EPSS 1.06%
- Published 28.10.2010 00:00:03
- Last modified 11.04.2025 00:51:21
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted mes...
- EPSS 2.08%
- Published 30.07.2010 13:26:15
- Last modified 11.04.2025 00:51:21
The clientautoresp function in family_icbm.c in the oscar protocol plugin in libpurple in Pidgin before 2.7.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via an X-Status message that...