Pidgin

Pidgin

86 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.71%
  • Veröffentlicht 01.07.2008 22:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.

  • EPSS 1.01%
  • Veröffentlicht 01.07.2008 22:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Memory leak in Pidgin 2.0.0, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via malformed XML documents. NOTE: this issue has been disputed by the upstream vendor, who states: "I was never able ...

  • EPSS 17.67%
  • Veröffentlicht 01.07.2008 22:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_slplink_process_msg function.

  • EPSS 1.37%
  • Veröffentlicht 29.10.2007 22:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.

  • EPSS 1.45%
  • Veröffentlicht 01.10.2007 20:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an in...

  • EPSS 0.47%
  • Veröffentlicht 17.07.2007 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to execute certain commands via unspecified vectors, aka ZD-00000035. NOTE: this information is based upon a vague ...