Pidgin kayıtları
pidgin üreticisine ait 91 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %91,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation20
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer18
- CWE-399 Resource Management Errors11
- CWE-125 Out-of-bounds Read8
- CWE-189 Numeric Errors5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
91 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2009-2694Kavram kanıtı | The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Apidgin · pidgin · CWE-399 | Kritik10,0 | — | %20,3 | 21 Ağu 2009 |
44Planlayın | CVE-2013-6490Kavram kanıtı | The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Lengtpidgin · pidgin · CWE-119 | Kritik10,0 | — | %14,8 | 6 Şub 2014 |
41Planlayın | CVE-2009-1376Kavram kanıtı | Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c andpidgin · pidgin · CWE-189 | Kritik9,3 | — | %13,3 | 26 May 2009 |
41Planlayın | CVE-2017-2640İstismar yok | An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content.pidgin · pidgin · CWE-787 | Kritik9,8 | — | %6,3 | 27 Tem 2018 |
40Planlayın | CVE-2016-1000030İstismar yok | Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutlpidgin · pidgin · CWE-295 | Kritik9,8 | — | %1,8 | 5 Eyl 2018 |
38İzleyin | CVE-2011-3185İstismar yok | gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a messapidgin · pidgin · CWE-20 | Kritik9,3 | — | %4,8 | 29 Ağu 2011 |
38İzleyin | CVE-2009-2404İstismar yok | Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunmozilla · network security services · CWE-119 | Kritik9,3 | — | %4,2 | 3 Ağu 2009 |
38İzleyin | CVE-2013-6486İstismar yok | gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing apidgin · pidgin · CWE-20 | Kritik9,3 | — | %3,8 | 6 Şub 2014 |
37İzleyin | CVE-2007-3841İstismar yok | Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to expidgin · pidgin | Kritik9,0 | — | %2,2 | 17 Tem 2007 |
35İzleyin | CVE-2016-2379İstismar yok | The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leverapidgin · mxit · CWE-326 | Yüksek8,8 | — | %0,4 | 29 Mar 2017 |
34İzleyin | CVE-2010-0013Kavram kanıtı | Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers tadium · adium · CWE-22 | Yüksek7,5 | — | %12,5 | 9 Oca 2010 |
33İzleyin | CVE-2016-2368İstismar yok | Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | Yüksek8,1 | — | %4,6 | 6 Oca 2017 |
33İzleyin | CVE-2016-2376İstismar yok | A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | Yüksek8,1 | — | %3,7 | 6 Oca 2017 |
33İzleyin | CVE-2016-2374İstismar yok | An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-125 | Yüksek8,1 | — | %3,2 | 6 Oca 2017 |
33İzleyin | CVE-2016-2371İstismar yok | An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-787 | Yüksek8,1 | — | %3,2 | 6 Oca 2017 |
33İzleyin | CVE-2016-2377İstismar yok | A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.pidgin · pidgin · CWE-119 | Yüksek8,1 | — | %2,6 | 6 Oca 2017 |
33İzleyin | CVE-2016-2378İstismar yok | A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin.pidgin · pidgin · CWE-119 | Yüksek8,1 | — | %2,5 | 6 Oca 2017 |
32İzleyin | CVE-2013-6487İstismar yok | Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have apidgin · pidgin · CWE-189 | Yüksek7,5 | — | %8,2 | 6 Şub 2014 |
32İzleyin | CVE-2012-3374İstismar yok | Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary copidgin · pidgin · CWE-119 | Yüksek7,5 | — | %6,4 | 7 Tem 2012 |
31İzleyin | CVE-2012-2369İstismar yok | Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.pidgin · pidgin · CWE-134 | Yüksek7,5 | — | %3,5 | 23 May 2012 |
29İzleyin | CVE-2009-1373İstismar yok | Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbpidgin · pidgin · CWE-119 | Yüksek7,1 | — | %4,3 | 26 May 2009 |
28İzleyin | CVE-2008-2927İstismar yok | Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c andpidgin · pidgin · CWE-189 | Orta6,8 | — | %4,3 | 7 Tem 2008 |
28İzleyin | CVE-2013-0272İstismar yok | Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code vpidgin · pidgin · CWE-119 | Orta6,8 | — | %2,9 | 16 Şub 2013 |
27İzleyin | CVE-2008-3532İstismar yok | The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user intpidgin · pidgin · CWE-310 | Orta6,8 | — | %1,6 | 8 Ağu 2008 |
27İzleyin | CVE-2019-25544İstismar yok | Pidgin 2.13.0 Denial of Service via Malformed Usernamepidgin · pidgin · CWE-807 | Orta6,9 | — | %0,2 | 21 Mar 2026 |
- CVE-2009-269446Planlayın
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and A
KritikCVSS 10,0Kavram kanıtıEPSS %20pidgin · pidgin21 Ağu 2009
- CVE-2013-649044Planlayın
The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Lengt
KritikCVSS 10,0Kavram kanıtıEPSS %15pidgin · pidgin6 Şub 2014
- CVE-2009-137641Planlayın
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and
KritikCVSS 9,3Kavram kanıtıEPSS %13pidgin · pidgin26 May 2009
- CVE-2017-264041Planlayın
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content.
KritikCVSS 9,8İstismar yokEPSS %6pidgin · pidgin27 Tem 2018
- CVE-2016-100003040Planlayın
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl
KritikCVSS 9,8İstismar yokEPSS %2pidgin · pidgin5 Eyl 2018
- CVE-2011-318538İzleyin
gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a messa
KritikCVSS 9,3İstismar yokEPSS %5pidgin · pidgin29 Ağu 2011
- CVE-2009-240438İzleyin
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thun
KritikCVSS 9,3İstismar yokEPSS %4mozilla · network security services3 Ağu 2009
- CVE-2013-648638İzleyin
gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a
KritikCVSS 9,3İstismar yokEPSS %4pidgin · pidgin6 Şub 2014
- CVE-2007-384137İzleyin
Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to ex
KritikCVSS 9,0İstismar yokEPSS %2pidgin · pidgin17 Tem 2007
- CVE-2016-237935İzleyin
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by levera
YüksekCVSS 8,8İstismar yokEPSS %0pidgin · mxit29 Mar 2017
- CVE-2010-001334İzleyin
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers t
YüksekCVSS 7,5Kavram kanıtıEPSS %12adium · adium9 Oca 2010
- CVE-2016-236833İzleyin
Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin.
YüksekCVSS 8,1İstismar yokEPSS %5pidgin · pidgin6 Oca 2017
- CVE-2016-237633İzleyin
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.
YüksekCVSS 8,1İstismar yokEPSS %4pidgin · pidgin6 Oca 2017
- CVE-2016-237433İzleyin
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin.
YüksekCVSS 8,1İstismar yokEPSS %3pidgin · pidgin6 Oca 2017
- CVE-2016-237133İzleyin
An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin.
YüksekCVSS 8,1İstismar yokEPSS %3pidgin · pidgin6 Oca 2017
- CVE-2016-237733İzleyin
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.
YüksekCVSS 8,1İstismar yokEPSS %3pidgin · pidgin6 Oca 2017
- CVE-2016-237833İzleyin
A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin.
YüksekCVSS 8,1İstismar yokEPSS %3pidgin · pidgin6 Oca 2017
- CVE-2013-648732İzleyin
Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have a
YüksekCVSS 7,5İstismar yokEPSS %8pidgin · pidgin6 Şub 2014
- CVE-2012-337432İzleyin
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary co
YüksekCVSS 7,5İstismar yokEPSS %6pidgin · pidgin7 Tem 2012
- CVE-2012-236931İzleyin
Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.
YüksekCVSS 7,5İstismar yokEPSS %4pidgin · pidgin23 May 2012
- CVE-2009-137329İzleyin
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arb
YüksekCVSS 7,1İstismar yokEPSS %4pidgin · pidgin26 May 2009
- CVE-2008-292728İzleyin
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and
OrtaCVSS 6,8İstismar yokEPSS %4pidgin · pidgin7 Tem 2008
- CVE-2013-027228İzleyin
Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code v
OrtaCVSS 6,8İstismar yokEPSS %3pidgin · pidgin16 Şub 2013
- CVE-2008-353227İzleyin
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user int
OrtaCVSS 6,8İstismar yokEPSS %2pidgin · pidgin8 Ağu 2008
- CVE-2019-2554427İzleyin
Pidgin 2.13.0 Denial of Service via Malformed Username
OrtaCVSS 6,9İstismar yokEPSS %0pidgin · pidgin21 Mar 2026