Pidgin records
91 published records for vendor pidgin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 91.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation20
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer18
- CWE-399 Resource Management Errors11
- CWE-125 Out-of-bounds Read8
- CWE-189 Numeric Errors5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
91 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2009-2694Proof of concept | The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Apidgin · pidgin · CWE-399 | Critical10.0 | — | 20.3% | Aug 21, 2009 |
44Plan | CVE-2013-6490Proof of concept | The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Lengtpidgin · pidgin · CWE-119 | Critical10.0 | — | 14.8% | Feb 6, 2014 |
41Plan | CVE-2009-1376Proof of concept | Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c andpidgin · pidgin · CWE-189 | Critical9.3 | — | 13.3% | May 26, 2009 |
41Plan | CVE-2017-2640No exploit | An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content.pidgin · pidgin · CWE-787 | Critical9.8 | — | 6.3% | Jul 27, 2018 |
40Plan | CVE-2016-1000030No exploit | Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutlpidgin · pidgin · CWE-295 | Critical9.8 | — | 1.8% | Sep 5, 2018 |
38Monitor | CVE-2011-3185No exploit | gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a messapidgin · pidgin · CWE-20 | Critical9.3 | — | 4.8% | Aug 29, 2011 |
38Monitor | CVE-2009-2404No exploit | Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunmozilla · network security services · CWE-119 | Critical9.3 | — | 4.2% | Aug 3, 2009 |
38Monitor | CVE-2013-6486No exploit | gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing apidgin · pidgin · CWE-20 | Critical9.3 | — | 3.8% | Feb 6, 2014 |
37Monitor | CVE-2007-3841No exploit | Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to expidgin · pidgin | Critical9.0 | — | 2.2% | Jul 17, 2007 |
35Monitor | CVE-2016-2379No exploit | The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leverapidgin · mxit · CWE-326 | High8.8 | — | 0.4% | Mar 29, 2017 |
34Monitor | CVE-2010-0013Proof of concept | Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers tadium · adium · CWE-22 | High7.5 | — | 12.5% | Jan 9, 2010 |
33Monitor | CVE-2016-2368No exploit | Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | High8.1 | — | 4.6% | Jan 6, 2017 |
33Monitor | CVE-2016-2376No exploit | A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | High8.1 | — | 3.7% | Jan 6, 2017 |
33Monitor | CVE-2016-2374No exploit | An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-125 | High8.1 | — | 3.2% | Jan 6, 2017 |
33Monitor | CVE-2016-2371No exploit | An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-787 | High8.1 | — | 3.2% | Jan 6, 2017 |
33Monitor | CVE-2016-2377No exploit | A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | High8.1 | — | 2.6% | Jan 6, 2017 |
33Monitor | CVE-2016-2378No exploit | A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin.pidgin · pidgin · CWE-119 | High8.1 | — | 2.5% | Jan 6, 2017 |
32Monitor | CVE-2013-6487No exploit | Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have apidgin · pidgin · CWE-189 | High7.5 | — | 8.2% | Feb 6, 2014 |
32Monitor | CVE-2012-3374No exploit | Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary copidgin · pidgin · CWE-119 | High7.5 | — | 6.4% | Jul 7, 2012 |
31Monitor | CVE-2012-2369No exploit | Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.pidgin · pidgin · CWE-134 | High7.5 | — | 3.5% | May 23, 2012 |
29Monitor | CVE-2009-1373No exploit | Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbpidgin · pidgin · CWE-119 | High7.1 | — | 4.3% | May 26, 2009 |
28Monitor | CVE-2008-2927No exploit | Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c andpidgin · pidgin · CWE-189 | Medium6.8 | — | 4.3% | Jul 7, 2008 |
28Monitor | CVE-2013-0272No exploit | Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code vpidgin · pidgin · CWE-119 | Medium6.8 | — | 2.9% | Feb 16, 2013 |
27Monitor | CVE-2008-3532No exploit | The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user intpidgin · pidgin · CWE-310 | Medium6.8 | — | 1.6% | Aug 8, 2008 |
27Monitor | CVE-2019-25544No exploit | Pidgin 2.13.0 Denial of Service via Malformed Usernamepidgin · pidgin · CWE-807 | Medium6.9 | — | 0.2% | Mar 21, 2026 |
- CVE-2009-269446Plan
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and A
CriticalCVSS 10.0Proof of conceptEPSS 20%pidgin · pidginAug 21, 2009
- CVE-2013-649044Plan
The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Lengt
CriticalCVSS 10.0Proof of conceptEPSS 15%pidgin · pidginFeb 6, 2014
- CVE-2009-137641Plan
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and
CriticalCVSS 9.3Proof of conceptEPSS 13%pidgin · pidginMay 26, 2009
- CVE-2017-264041Plan
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content.
CriticalCVSS 9.8No exploitEPSS 6%pidgin · pidginJul 27, 2018
- CVE-2016-100003040Plan
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl
CriticalCVSS 9.8No exploitEPSS 2%pidgin · pidginSep 5, 2018
- CVE-2011-318538Monitor
gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a messa
CriticalCVSS 9.3No exploitEPSS 5%pidgin · pidginAug 29, 2011
- CVE-2009-240438Monitor
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thun
CriticalCVSS 9.3No exploitEPSS 4%mozilla · network security servicesAug 3, 2009
- CVE-2013-648638Monitor
gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a
CriticalCVSS 9.3No exploitEPSS 4%pidgin · pidginFeb 6, 2014
- CVE-2007-384137Monitor
Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to ex
CriticalCVSS 9.0No exploitEPSS 2%pidgin · pidginJul 17, 2007
- CVE-2016-237935Monitor
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by levera
HighCVSS 8.8No exploitEPSS 0%pidgin · mxitMar 29, 2017
- CVE-2010-001334Monitor
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers t
HighCVSS 7.5Proof of conceptEPSS 12%adium · adiumJan 9, 2010
- CVE-2016-236833Monitor
Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin.
HighCVSS 8.1No exploitEPSS 5%pidgin · pidginJan 6, 2017
- CVE-2016-237633Monitor
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.
HighCVSS 8.1No exploitEPSS 4%pidgin · pidginJan 6, 2017
- CVE-2016-237433Monitor
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin.
HighCVSS 8.1No exploitEPSS 3%pidgin · pidginJan 6, 2017
- CVE-2016-237133Monitor
An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin.
HighCVSS 8.1No exploitEPSS 3%pidgin · pidginJan 6, 2017
- CVE-2016-237733Monitor
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.
HighCVSS 8.1No exploitEPSS 3%pidgin · pidginJan 6, 2017
- CVE-2016-237833Monitor
A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin.
HighCVSS 8.1No exploitEPSS 3%pidgin · pidginJan 6, 2017
- CVE-2013-648732Monitor
Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have a
HighCVSS 7.5No exploitEPSS 8%pidgin · pidginFeb 6, 2014
- CVE-2012-337432Monitor
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary co
HighCVSS 7.5No exploitEPSS 6%pidgin · pidginJul 7, 2012
- CVE-2012-236931Monitor
Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.
HighCVSS 7.5No exploitEPSS 4%pidgin · pidginMay 23, 2012
- CVE-2009-137329Monitor
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arb
HighCVSS 7.1No exploitEPSS 4%pidgin · pidginMay 26, 2009
- CVE-2008-292728Monitor
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and
MediumCVSS 6.8No exploitEPSS 4%pidgin · pidginJul 7, 2008
- CVE-2013-027228Monitor
Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code v
MediumCVSS 6.8No exploitEPSS 3%pidgin · pidginFeb 16, 2013
- CVE-2008-353227Monitor
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user int
MediumCVSS 6.8No exploitEPSS 2%pidgin · pidginAug 8, 2008
- CVE-2019-2554427Monitor
Pidgin 2.13.0 Denial of Service via Malformed Username
MediumCVSS 6.9No exploitEPSS 0%pidgin · pidginMar 21, 2026