Page 7 of 90 results (0.002 seconds)

CVSS: 6.5EPSS: 1%CPEs: 34EXPL: 0

27 Oct 2010 — libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support. libpurple en Pidgin anterior a v2.7.4 no valida correctamente el valor de retorno de la función purple_base64_decode, lo cual permite a usuarios remotos autent... • http://developer.pidgin.im/viewmtn/revision/info/b01c6a1f7fe4d86b83f5f10917b3cb713989cfcc • CWE-20: Improper Input Validation •

CVSS: 9.8EPSS: 0%CPEs: 5EXPL: 0

08 Oct 2010 — The notify function in pidgin-knotify.c in the pidgin-knotify plugin 0.2.1 and earlier for Pidgin allows remote attackers to execute arbitrary commands via shell metacharacters in a message. La función de notificación en pidgin-knotify.c en el plugin pidgin-knotify v0.2.1 y anteriores para Pidgin permite a atacantes remotos ejecutar comandos arbitrarios usando metacaracteres encubiertos en un mensaje. A vulnerability in pidgin-knotify might allow remote attackers to execute arbitrary code. Versions 0.2.1 an... • http://code.google.com/p/pidgin-knotify/issues/detail?id=1 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 6.5EPSS: 2%CPEs: 32EXPL: 0

29 Jul 2010 — The clientautoresp function in family_icbm.c in the oscar protocol plugin in libpurple in Pidgin before 2.7.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via an X-Status message that lacks the expected end tag for a (1) desc or (2) title element. La función clientautoresp de family_icbm.c en el complemento de protocolo oscar en libpurple de Pidgin en versiones anteriores a la v2.7.2 permite a usuarios autenticados remotos provocar una deneg... • http://developer.pidgin.im/viewmtn/revision/diff/fcb70f7c12120206d30ad33223ff85be7b226d1c/with/8e8ff246492e45af8f8d0808296d6f2906794dc0/libpurple/protocols/oscar/family_icbm.c • CWE-399: Resource Management Errors •

CVSS: 6.5EPSS: 3%CPEs: 5EXPL: 0

14 May 2010 — The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message. La función msn_emoticon_msg en slp.c en el plugin MSN protocol en libpurple en Pidgin en versiones anteriores a la 2.7.0 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) mediante un emoticono personalizado en... • http://developer.pidgin.im/viewmtn/revision/diff/884d44222e8c81ecec51c25e07d005e002a5479b/with/894460d22c434e73d60b71ec031611988e687c8b/libpurple/protocols/msn/slp.c • CWE-20: Improper Input Validation CWE-476: NULL Pointer Dereference •

CVSS: 7.5EPSS: 3%CPEs: 29EXPL: 0

24 Feb 2010 — libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing
sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname. libpurple en Finch en Pidgin anterior a v2.6.6, cuando se usa un chat XMPP multi-usuario, no valida adecuadamente los alias (nicknames) que contienen la secuencia
, lo que permite a atacantes remotos provocar una denegación de servicio (caída de aplica... • http://developer.pidgin.im/wiki/ChangeLog • CWE-20: Improper Input Validation •

CVSS: 7.5EPSS: 8%CPEs: 29EXPL: 0

24 Feb 2010 — gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat. gtkimhtml.c en Pidgin anterior a v2.6.6, permite a atacantes remotos provocar una denegación de servicio (consumo de CPU y cuelgue de aplicación) mediante el envío de varios smileys en una conversación de (1) IM o (2) chat. • http://developer.pidgin.im/wiki/ChangeLog • CWE-399: Resource Management Errors •

CVSS: 9.8EPSS: 8%CPEs: 30EXPL: 0

09 Jan 2010 — slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013. El archivo slp.c en el plugin del protocolo MSN en la biblioteca libpurple en Pidgin anterior a versión 2.6.6, incluyendo la versión 2.6.4, y Adium versión 1.3.8, permite a los ... • http://blogs.sun.com/security/entry/cve_2010_0277_malformed_msn • CWE-399: Resource Management Errors •

CVSS: 7.5EPSS: 12%CPEs: 10EXPL: 1

09 Jan 2010 — Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon. Vulne... • https://www.exploit-db.com/exploits/11203 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 7%CPEs: 46EXPL: 0

20 Oct 2009 — The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client. El conponente OSCAR protocol en libpurple en Pidgin v2.6.3 y Adium anterior v1.3.7, permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de datos de una lista de contactos manipulada para (1) ICQ y probablemete... • http://developer.pidgin.im/ticket/10481 • CWE-399: Resource Management Errors •

CVSS: 7.5EPSS: 0%CPEs: 37EXPL: 0

08 Sep 2009 — libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string. libpurple/protocols/irc/msgs.c en el complemento (plugin) de protocolo IRC de libpurple en Pidgin v2.6.2 permite causar a servidores IRC remotos para una denegación de servicio (mediante una desreferencia a puntero NULL y caida de la aplicación) a través de un mensaj... • http://developer.pidgin.im/viewmtn/revision/info/ad2c6ee53ec9122b25aeb1f918db53be69bdeac3 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-476: NULL Pointer Dereference •