Search CVE reports


Toggle filters

71 – 80 of 92 results


CVE-2010-0013

Medium priority
Fixed

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka...

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2009-3615

Low priority
Fixed

The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as...

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2009-3085

Low priority
Fixed

The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash)...

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2009-3084

Low priority
Not affected

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application...

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2009-3083

Low priority
Fixed

The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash)...

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2009-3026

Medium priority
Fixed

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes...

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2009-3025

Medium priority
Not affected

Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2009-2703

Low priority
Fixed

libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a...

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2009-2694

Medium priority

Some fixes available 3 of 4

The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a...

2 affected packages

gaim, pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gaim
pidgin
Show less packages

CVE-2009-1889

Medium priority
Fixed

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web...

1 affected package

pidgin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages