Skip to content
Noroxi

Pidgin records

91 published records for vendor pidgin.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
12
With a fix record
91.2%
Median publish → KEV
No record has entered KEV

All records

91 records
  • The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and A

    CriticalCVSS 10.0Proof of conceptEPSS 20%

    pidgin · pidginAug 21, 2009

  • The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Lengt

    CriticalCVSS 10.0Proof of conceptEPSS 15%

    pidgin · pidginFeb 6, 2014

  • Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and

    CriticalCVSS 9.3Proof of conceptEPSS 13%

    pidgin · pidginMay 26, 2009

  • An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content.

    CriticalCVSS 9.8No exploitEPSS 6%

    pidgin · pidginJul 27, 2018

  • Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl

    CriticalCVSS 9.8No exploitEPSS 2%

    pidgin · pidginSep 5, 2018

  • CVE-2011-3185
    38Monitor

    gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a messa

    CriticalCVSS 9.3No exploitEPSS 5%

    pidgin · pidginAug 29, 2011

  • CVE-2009-2404
    38Monitor

    Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thun

    CriticalCVSS 9.3No exploitEPSS 4%

    mozilla · network security servicesAug 3, 2009

  • CVE-2013-6486
    38Monitor

    gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a

    CriticalCVSS 9.3No exploitEPSS 4%

    pidgin · pidginFeb 6, 2014

  • CVE-2007-3841
    37Monitor

    Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to ex

    CriticalCVSS 9.0No exploitEPSS 2%

    pidgin · pidginJul 17, 2007

  • CVE-2016-2379
    35Monitor

    The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by levera

    HighCVSS 8.8No exploitEPSS 0%

    pidgin · mxitMar 29, 2017

  • CVE-2010-0013
    34Monitor

    Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers t

    HighCVSS 7.5Proof of conceptEPSS 12%

    adium · adiumJan 9, 2010

  • CVE-2016-2368
    33Monitor

    Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin.

    HighCVSS 8.1No exploitEPSS 5%

    pidgin · pidginJan 6, 2017

  • CVE-2016-2376
    33Monitor

    A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.

    HighCVSS 8.1No exploitEPSS 4%

    pidgin · pidginJan 6, 2017

  • CVE-2016-2374
    33Monitor

    An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin.

    HighCVSS 8.1No exploitEPSS 3%

    pidgin · pidginJan 6, 2017

  • CVE-2016-2371
    33Monitor

    An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin.

    HighCVSS 8.1No exploitEPSS 3%

    pidgin · pidginJan 6, 2017

  • CVE-2016-2377
    33Monitor

    A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.

    HighCVSS 8.1No exploitEPSS 3%

    pidgin · pidginJan 6, 2017

  • CVE-2016-2378
    33Monitor

    A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin.

    HighCVSS 8.1No exploitEPSS 3%

    pidgin · pidginJan 6, 2017

  • CVE-2013-6487
    32Monitor

    Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have a

    HighCVSS 7.5No exploitEPSS 8%

    pidgin · pidginFeb 6, 2014

  • CVE-2012-3374
    32Monitor

    Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary co

    HighCVSS 7.5No exploitEPSS 6%

    pidgin · pidginJul 7, 2012

  • CVE-2012-2369
    31Monitor

    Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.

    HighCVSS 7.5No exploitEPSS 4%

    pidgin · pidginMay 23, 2012

  • CVE-2009-1373
    29Monitor

    Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arb

    HighCVSS 7.1No exploitEPSS 4%

    pidgin · pidginMay 26, 2009

  • CVE-2008-2927
    28Monitor

    Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and

    MediumCVSS 6.8No exploitEPSS 4%

    pidgin · pidginJul 7, 2008

  • CVE-2013-0272
    28Monitor

    Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code v

    MediumCVSS 6.8No exploitEPSS 3%

    pidgin · pidginFeb 16, 2013

  • CVE-2008-3532
    27Monitor

    The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user int

    MediumCVSS 6.8No exploitEPSS 2%

    pidgin · pidginAug 8, 2008

  • Pidgin 2.13.0 Denial of Service via Malformed Username

    MediumCVSS 6.9No exploitEPSS 0%

    pidgin · pidginMar 21, 2026