
CVE-2009-3615 – Pidgin: Invalid pointer dereference (crash) after receiving contacts from SIM IM client
https://notcve.org/view.php?id=CVE-2009-3615
20 Oct 2009 — The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client. El conponente OSCAR protocol en libpurple en Pidgin v2.6.3 y Adium anterior v1.3.7, permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de datos de una lista de contactos manipulada para (1) ICQ y probablemete... • http://developer.pidgin.im/ticket/10481 • CWE-399: Resource Management Errors •

CVE-2008-7190
https://notcve.org/view.php?id=CVE-2008-7190
09 Sep 2009 — Unspecified vulnerability in Adium before 1.2 has unknown impact and attack vectors related to javascript: URLs, possibly cross-site scripting (XSS). Vulnerabilidad sin especificar en Adium anterior a v1.2 tiene un impacto y vectores de ataque desconocidos relacionados con el JavaScript: Urls, posiblemente la ejecución de secuencias de comandos en sitios cruzados (XSS). • http://osvdb.org/41802 •

CVE-2009-2694 – Pidgin MSN 2.5.8 - Remote Code Execution
https://notcve.org/view.php?id=CVE-2009-2694
20 Aug 2009 — The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376. La función msn_slplink_process_ms... • https://www.exploit-db.com/exploits/9615 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-399: Resource Management Errors •

CVE-2008-2927 – Multiple Vendor libpurple MSN Protocol SLP Message Heap Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2008-2927
07 Jul 2008 — Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955. Múltiples desbordamiento de enteros en las funciones msn_slplink_process_msg en el manejador de protocolo MSN en los archivos (1) libpu... • http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240086ee79e4a08fd8/libpurple/protocols/msn/slplink.c • CWE-189: Numeric Errors CWE-190: Integer Overflow or Wraparound •