Записи Pidgin
91 опубликованных записей вендора pidgin.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 91,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation20
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer18
- CWE-399 Resource Management Errors11
- CWE-125 Out-of-bounds Read8
- CWE-189 Numeric Errors5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
91 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2009-2694Proof of concept | The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Apidgin · pidgin · CWE-399 | Критическая10,0 | — | 20,3 % | 21 авг. 2009 г. |
44В плане | CVE-2013-6490Proof of concept | The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Lengtpidgin · pidgin · CWE-119 | Критическая10,0 | — | 14,8 % | 6 февр. 2014 г. |
41В плане | CVE-2009-1376Proof of concept | Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c andpidgin · pidgin · CWE-189 | Критическая9,3 | — | 13,3 % | 26 мая 2009 г. |
41В плане | CVE-2017-2640Эксплойта нет | An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content.pidgin · pidgin · CWE-787 | Критическая9,8 | — | 6,3 % | 27 июл. 2018 г. |
40В плане | CVE-2016-1000030Эксплойта нет | Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutlpidgin · pidgin · CWE-295 | Критическая9,8 | — | 1,8 % | 5 сент. 2018 г. |
38Наблюдать | CVE-2011-3185Эксплойта нет | gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a messapidgin · pidgin · CWE-20 | Критическая9,3 | — | 4,8 % | 29 авг. 2011 г. |
38Наблюдать | CVE-2009-2404Эксплойта нет | Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunmozilla · network security services · CWE-119 | Критическая9,3 | — | 4,2 % | 3 авг. 2009 г. |
38Наблюдать | CVE-2013-6486Эксплойта нет | gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing apidgin · pidgin · CWE-20 | Критическая9,3 | — | 3,8 % | 6 февр. 2014 г. |
37Наблюдать | CVE-2007-3841Эксплойта нет | Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to expidgin · pidgin | Критическая9,0 | — | 2,2 % | 17 июл. 2007 г. |
35Наблюдать | CVE-2016-2379Эксплойта нет | The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leverapidgin · mxit · CWE-326 | Высокая8,8 | — | 0,4 % | 29 мар. 2017 г. |
34Наблюдать | CVE-2010-0013Proof of concept | Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers tadium · adium · CWE-22 | Высокая7,5 | — | 12,5 % | 9 янв. 2010 г. |
33Наблюдать | CVE-2016-2368Эксплойта нет | Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | Высокая8,1 | — | 4,6 % | 6 янв. 2017 г. |
33Наблюдать | CVE-2016-2376Эксплойта нет | A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | Высокая8,1 | — | 3,7 % | 6 янв. 2017 г. |
33Наблюдать | CVE-2016-2374Эксплойта нет | An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-125 | Высокая8,1 | — | 3,2 % | 6 янв. 2017 г. |
33Наблюдать | CVE-2016-2371Эксплойта нет | An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-787 | Высокая8,1 | — | 3,2 % | 6 янв. 2017 г. |
33Наблюдать | CVE-2016-2377Эксплойта нет | A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | Высокая8,1 | — | 2,6 % | 6 янв. 2017 г. |
33Наблюдать | CVE-2016-2378Эксплойта нет | A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin.pidgin · pidgin · CWE-119 | Высокая8,1 | — | 2,5 % | 6 янв. 2017 г. |
32Наблюдать | CVE-2013-6487Эксплойта нет | Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have apidgin · pidgin · CWE-189 | Высокая7,5 | — | 8,2 % | 6 февр. 2014 г. |
32Наблюдать | CVE-2012-3374Эксплойта нет | Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary copidgin · pidgin · CWE-119 | Высокая7,5 | — | 6,4 % | 7 июл. 2012 г. |
31Наблюдать | CVE-2012-2369Эксплойта нет | Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.pidgin · pidgin · CWE-134 | Высокая7,5 | — | 3,5 % | 23 мая 2012 г. |
29Наблюдать | CVE-2009-1373Эксплойта нет | Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbpidgin · pidgin · CWE-119 | Высокая7,1 | — | 4,3 % | 26 мая 2009 г. |
28Наблюдать | CVE-2008-2927Эксплойта нет | Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c andpidgin · pidgin · CWE-189 | Средняя6,8 | — | 4,3 % | 7 июл. 2008 г. |
28Наблюдать | CVE-2013-0272Эксплойта нет | Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code vpidgin · pidgin · CWE-119 | Средняя6,8 | — | 2,9 % | 16 февр. 2013 г. |
27Наблюдать | CVE-2008-3532Эксплойта нет | The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user intpidgin · pidgin · CWE-310 | Средняя6,8 | — | 1,6 % | 8 авг. 2008 г. |
27Наблюдать | CVE-2019-25544Эксплойта нет | Pidgin 2.13.0 Denial of Service via Malformed Usernamepidgin · pidgin · CWE-807 | Средняя6,9 | — | 0,2 % | 21 мар. 2026 г. |
- CVE-2009-269446В плане
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and A
КритическаяCVSS 10,0Proof of conceptEPSS 20 %pidgin · pidgin21 авг. 2009 г.
- CVE-2013-649044В плане
The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Lengt
КритическаяCVSS 10,0Proof of conceptEPSS 15 %pidgin · pidgin6 февр. 2014 г.
- CVE-2009-137641В плане
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and
КритическаяCVSS 9,3Proof of conceptEPSS 13 %pidgin · pidgin26 мая 2009 г.
- CVE-2017-264041В плане
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %pidgin · pidgin27 июл. 2018 г.
- CVE-2016-100003040В плане
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pidgin · pidgin5 сент. 2018 г.
- CVE-2011-318538Наблюдать
gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a messa
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %pidgin · pidgin29 авг. 2011 г.
- CVE-2009-240438Наблюдать
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thun
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %mozilla · network security services3 авг. 2009 г.
- CVE-2013-648638Наблюдать
gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %pidgin · pidgin6 февр. 2014 г.
- CVE-2007-384137Наблюдать
Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to ex
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %pidgin · pidgin17 июл. 2007 г.
- CVE-2016-237935Наблюдать
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by levera
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %pidgin · mxit29 мар. 2017 г.
- CVE-2010-001334Наблюдать
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers t
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %adium · adium9 янв. 2010 г.
- CVE-2016-236833Наблюдать
Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin.
ВысокаяCVSS 8,1Эксплойта нетEPSS 5 %pidgin · pidgin6 янв. 2017 г.
- CVE-2016-237633Наблюдать
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.
ВысокаяCVSS 8,1Эксплойта нетEPSS 4 %pidgin · pidgin6 янв. 2017 г.
- CVE-2016-237433Наблюдать
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin.
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %pidgin · pidgin6 янв. 2017 г.
- CVE-2016-237133Наблюдать
An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin.
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %pidgin · pidgin6 янв. 2017 г.
- CVE-2016-237733Наблюдать
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %pidgin · pidgin6 янв. 2017 г.
- CVE-2016-237833Наблюдать
A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin.
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %pidgin · pidgin6 янв. 2017 г.
- CVE-2013-648732Наблюдать
Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have a
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %pidgin · pidgin6 февр. 2014 г.
- CVE-2012-337432Наблюдать
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary co
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %pidgin · pidgin7 июл. 2012 г.
- CVE-2012-236931Наблюдать
Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %pidgin · pidgin23 мая 2012 г.
- CVE-2009-137329Наблюдать
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arb
ВысокаяCVSS 7,1Эксплойта нетEPSS 4 %pidgin · pidgin26 мая 2009 г.
- CVE-2008-292728Наблюдать
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and
СредняяCVSS 6,8Эксплойта нетEPSS 4 %pidgin · pidgin7 июл. 2008 г.
- CVE-2013-027228Наблюдать
Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code v
СредняяCVSS 6,8Эксплойта нетEPSS 3 %pidgin · pidgin16 февр. 2013 г.
- CVE-2008-353227Наблюдать
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user int
СредняяCVSS 6,8Эксплойта нетEPSS 2 %pidgin · pidgin8 авг. 2008 г.
- CVE-2019-2554427Наблюдать
Pidgin 2.13.0 Denial of Service via Malformed Username
СредняяCVSS 6,9Эксплойта нетEPSS 0 %pidgin · pidgin21 мар. 2026 г.