Vulnerabilities > Pidgin

DATE CVE VULNERABILITY TITLE RISK
2012-03-15 CVE-2011-4939 Permissions, Privileges, and Access Controls vulnerability in Pidgin
The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.
network
low complexity
pidgin CWE-264
6.4
2011-12-25 CVE-2011-4601 Improper Input Validation vulnerability in Pidgin
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.
network
low complexity
pidgin CWE-20
5.0
2011-12-17 CVE-2011-4603 Improper Input Validation vulnerability in Pidgin
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
network
low complexity
pidgin CWE-20
5.0
2011-12-17 CVE-2011-4602 Improper Input Validation vulnerability in Pidgin
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
network
low complexity
pidgin CWE-20
5.0
2011-11-04 CVE-2011-3594 Buffer Errors vulnerability in Pidgin Libpurple and Pidgin
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.
network
pidgin CWE-119
4.3
2011-08-29 CVE-2011-3185 Improper Input Validation vulnerability in Pidgin
gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.
network
microsoft pidgin CWE-20
critical
9.3
2011-08-29 CVE-2011-3184 Resource Management Errors vulnerability in Pidgin
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.
network
pidgin CWE-399
4.3
2011-08-29 CVE-2011-2943 Denial of Service and Security Bypass vulnerability in Pidgin Libpurple and Pidgin
The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response.
network
pidgin
4.3
2011-01-07 CVE-2010-4528 Improper Input Validation vulnerability in Pidgin Libpurple and Pidgin
directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a short p2pv2 packet in a DirectConnect (aka direct connection) session.
network
low complexity
pidgin CWE-20
4.0
2010-10-28 CVE-2010-3711 Improper Input Validation vulnerability in Pidgin
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.
network
low complexity
pidgin CWE-20
4.0