cbcvebase.

Debian Pidgin vulnerabilities

80 known vulnerabilities affecting debian/pidgin.

Total CVEs
80
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM43LOW26

Vulnerabilities

Page 2 of 4
CVE-2016-2372P4MEDIUMCVSS 5.9fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2372 [MEDIUM] CVE-2016-2372: pidgin - An information leak exists in the handling of the MXIT protocol in Pidgin. Speci... An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of servi
debian
CVE-2013-6483P4MEDIUMCVSS 6.4fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6483 [MEDIUM] CVE-2013-6483: pidgin - The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly ... The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply. Scope: local bookworm: resolved (fixed
debian
CVE-2008-3532P4MEDIUMCVSS 6.8fixed in pidgin 2.4.3-2 (bookworm)2008
CVE-2008-3532 [MEDIUM] CVE-2008-3532: pidgin - The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, wh... The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service. Scope: local bookworm: resolved (fixed in 2.4.3-2) bullseye: resolved (fixed in 2.4.3-2) forky: resolved (fixed in 2.4.3-2) sid: resolved (fixed in 2.4.3-2) trixie:
debian
CVE-2016-2366P4MEDIUMCVSS 5.9fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2366 [MEDIUM] CVE-2016-2366: pidgin - A denial of service vulnerability exists in the handling of the MXIT protocol in... A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash. Scope: local bookworm: resolved (fixed in
debian
CVE-2016-2365P4MEDIUMCVSS 5.9fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2365 [MEDIUM] CVE-2016-2365: pidgin - A denial of service vulnerability exists in the handling of the MXIT protocol in... A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash. Scope: local bookworm: resolved (fix
debian
CVE-2016-2370P4MEDIUMCVSS 5.9fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2370 [MEDIUM] CVE-2016-2370: pidgin - A denial of service vulnerability exists in the handling of the MXIT protocol in... A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A malicious server or man-in-the-middle attacker can send invalid data to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.11.0-1) bullseye: resolved (fixed
debian
CVE-2016-2375P4MEDIUMCVSS 5.3fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2375 [MEDIUM] CVE-2016-2375: pidgin - An exploitable out-of-bounds read exists in the handling of the MXIT protocol in... An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure. Scope: local bookworm: resolved (fixed in 2.11.0-1) bullseye: resolved (fixed in 2.11.0-1) forky: resolved (fixed in 2.11.0-1) sid: resolved (fixed in 2.11.0-1) trixie: resolved (fixe
debian
CVE-2016-2373P4MEDIUMCVSS 5.9fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2373 [MEDIUM] CVE-2016-2373: pidgin - A denial of service vulnerability exists in the handling of the MXIT protocol in... A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can send an invalid mood to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.11.0-1) bullseye: resolved (fixed in 2.11.0-1) forky:
debian
CVE-2016-2369P4MEDIUMCVSS 5.9fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2369 [MEDIUM] CVE-2016-2369: pidgin - A NULL pointer dereference vulnerability exists in the handling of the MXIT prot... A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a denial of service vulnerability. A malicious server can send a packet starting with a NULL byte triggering the vulnerability. Scope: local bookworm: resolved (fixed in 2.11.0-1) bullseye: resolve
debian
CVE-2016-2367P4MEDIUMCVSS 5.9fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2367 [MEDIUM] CVE-2016-2367: pidgin - An information leak exists in the handling of the MXIT protocol in Pidgin. Speci... An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle can send an invalid size for an avatar which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data
debian
CVE-2008-2957P4LOWCVSS 6.4fixed in pidgin 2.4.3-4 (bookworm)2008
CVE-2008-2957 [MEDIUM] CVE-2008-2957: pidgin - The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remo... The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL. Scope: local bookworm: resolved (fixed in 2.4.3-4) bullseye: resolved (fixed in 2.4.3-4) forky: resolved (fixed in 2.4.3-4)
debian
CVE-2013-0271P4MEDIUMCVSS 5.0fixed in pidgin 2.10.6-3 (bookworm)2013
CVE-2013-0271 [MEDIUM] CVE-2013-0271: pidgin - The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote... The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote attackers to create or overwrite files via a crafted (1) mxit or (2) mxit/imagestrips pathname. Scope: local bookworm: resolved (fixed in 2.10.6-3) bullseye: resolved (fixed in 2.10.6-3) forky: resolved (fixed in 2.10.6-3) sid: resolved (fixed in 2.10.6-3) trixie: resolved (fixed in 2.10
debian
CVE-2014-3698P4MEDIUMCVSS 5.0fixed in pidgin 2.10.10-1 (bookworm)2014
CVE-2014-3698 [MEDIUM] CVE-2014-3698: pidgin - The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in lib... The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sensitive information from process memory via a crafted XMPP message. Scope: local bookworm: resolved (fixed in 2.10.10-1) bullseye: resolved (fixed in 2.10.10-1) forky: resolved (fixed in 2.10.10-1) sid: resolved (fixed in
debian
CVE-2011-4939P4MEDIUMCVSS 6.4fixed in pidgin 2.10.2-1 (bookworm)2011
CVE-2011-4939 [MEDIUM] CVE-2011-4939: pidgin - The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 a... The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room. Scope: local bookworm: resolved (fixed in 2.10.2-1) bullseye: resolved (fixed in 2.10.2-1) forky: resolved (fixed in 2.10.2-1) sid: resol
debian
CVE-2013-6489P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6489 [MEDIUM] CVE-2013-6489: pidgin - Integer signedness error in the MXit functionality in Pidgin before 2.10.8 allow... Integer signedness error in the MXit functionality in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (segmentation fault) via a crafted emoticon value, which triggers an integer overflow and a buffer overflow. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixed in 2.10.8-1) sid:
debian
CVE-2013-6481P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6481 [MEDIUM] CVE-2013-6481: pidgin - libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote attack... libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (crash) via a Yahoo! P2P message with a crafted length field, which triggers a buffer over-read. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixed in 2.10.8-1) sid: resolved (fixed in 2.10.8-1
debian
CVE-2011-4601P4LOWCVSS 5.0fixed in pidgin 2.10.1-1 (bookworm)2011
CVE-2011-4601 [MEDIUM] CVE-2011-4601: pidgin - family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10... family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition. Scope: local bookworm: resolved (fixed in 2.10.1-1) bullseye: res
debian
CVE-2012-6152P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2012
CVE-2012-6152 [MEDIUM] CVE-2012-6152: pidgin - The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properl... The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application crash) via crafted byte sequences. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixed in 2.10.8-1) sid: resolved (fixed in 2.10.8-1
debian
CVE-2009-3026P4LOWCVSS 5.0fixed in pidgin 2.6.1-1 (bookworm)2009
CVE-2009-3026 [MEDIUM] CVE-2009-3026: pidgin - protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other version... protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions. Scope: local bookworm: reso
debian
CVE-2010-0277P4LOWCVSS 7.5fixed in pidgin 2.6.6-1 (bookworm)2010
CVE-2010-0277 [HIGH] CVE-2010-0277: pidgin - slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including ... slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013. Scope: local bookworm: resolved (fix
debian
Debian Pidgin vulnerabilities | cvebase