Pidgin

Pidgin

86 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.17%
  • Published 17.12.2011 03:54:46
  • Last modified 11.04.2025 00:51:21

The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash)...

  • EPSS 1.46%
  • Published 17.12.2011 03:54:45
  • Last modified 11.04.2025 00:51:21

The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.

Exploit
  • EPSS 0.96%
  • Published 04.11.2011 21:55:07
  • Last modified 11.04.2025 00:51:21

The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use o...

  • EPSS 5.09%
  • Published 29.08.2011 17:55:01
  • Last modified 11.04.2025 00:51:21

gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.

  • EPSS 2.69%
  • Published 29.08.2011 17:55:01
  • Last modified 11.04.2025 00:51:21

The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and ap...

  • EPSS 3.96%
  • Published 29.08.2011 17:55:00
  • Last modified 11.04.2025 00:51:21

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL ...

  • EPSS 1.49%
  • Published 14.03.2011 19:55:02
  • Last modified 11.04.2025 00:51:21

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allo...

  • EPSS 2.69%
  • Published 07.01.2011 12:00:49
  • Last modified 11.04.2025 00:51:21

directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a short p2pv2 packet in a DirectConnec...

  • EPSS 1.06%
  • Published 28.10.2010 00:00:03
  • Last modified 11.04.2025 00:51:21

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted mes...

  • EPSS 2.08%
  • Published 30.07.2010 13:26:15
  • Last modified 11.04.2025 00:51:21

The clientautoresp function in family_icbm.c in the oscar protocol plugin in libpurple in Pidgin before 2.7.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via an X-Status message that...