cbcvebase.

Debian Pidgin vulnerabilities

80 known vulnerabilities affecting debian/pidgin.

Total CVEs
80
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM43LOW26

Vulnerabilities

Page 3 of 4
CVE-2013-6485P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6485 [MEDIUM] CVE-2013-6485: pidgin - Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTT... Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid chunk-size field in chunked transfer-coding data. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixed in 2.10.8
debian
CVE-2009-3615P4MEDIUMCVSS 5.0fixed in pidgin 2.6.3-1 (bookworm)2009
CVE-2009-3615 [MEDIUM] CVE-2009-3615: pidgin - The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1... The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client. Scope: local bookworm: resolved (fixed in 2.6.3-1) bullseye: resolved (fixed in 2.6.3-1) forky: resolved (fix
debian
CVE-2009-1374P4MEDIUMCVSS 5.0fixed in pidgin 2.5.6-1 (bookworm)2009
CVE-2009-1374 [MEDIUM] CVE-2009-1374: pidgin - Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5... Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet. Scope: local bookworm: resolved (fixed in 2.5.6-1) bullseye: resolved (fixed in 2.5.6-1) forky: resolved (fixed in 2.5.6-1) sid: resolved (fixed in 2.5.6-1) trixie: resolved (fixed in 2.5.6-1)
debian
CVE-2011-4603P4LOWCVSS 4.3fixed in pidgin 2.10.1-1 (bookworm)2011
CVE-2011-4603 [MEDIUM] CVE-2011-4603: pidgin - The silc_channel_message function in ops.c in the SILC protocol plugin in libpur... The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594. Scope: local bookworm: resolved (fixed in 2.10.1-
debian
CVE-2010-1624P4LOWCVSS 5.0fixed in pidgin 2.7.0-1 (bookworm)2010
CVE-2010-1624 [MEDIUM] CVE-2010-1624: pidgin - The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple i... The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message. Scope: local bookworm: resolved (fixed in 2.7.0-1) bullseye: resolved (fixed in 2.7.0-1) forky: resolved
debian
CVE-2013-6477P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6477 [MEDIUM] CVE-2013-6477: pidgin - Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow re... Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a crafted timestamp value in an XMPP message. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixed in 2.10.8-1) sid: resolved (fixed in 2.10.8-1) trixie: resolv
debian
CVE-2011-4602P4LOWCVSS 5.0fixed in pidgin 2.10.1-1 (bookworm)2011
CVE-2011-4602 [MEDIUM] CVE-2011-4602: pidgin - The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly ... The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message. Scope: local bookworm: resolved (fixed in 2.10.1-1) bullseye: resolved (fixed in 2.10.1-1) forky: resolved (fixed in 2.
debian
CVE-2014-3696P4MEDIUMCVSS 5.0fixed in pidgin 2.10.10-1 (bookworm)2014
CVE-2014-3696 [MEDIUM] CVE-2014-3696: pidgin - nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before ... nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a crafted server message that triggers a large memory allocation. Scope: local bookworm: resolved (fixed in 2.10.10-1) bullseye: resolved (fixed in 2.10.10-1) forky: resolved (fixed in 2.10.10-1) sid: resol
debian
CVE-2009-3083P4LOWCVSS 5.0fixed in pidgin 2.6.2-1 (bookworm)2009
CVE-2009-3083 [MEDIUM] CVE-2009-3083: pidgin - The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protoc... The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client. Scope: local bookwo
debian
CVE-2013-0273P4MEDIUMCVSS 5.0fixed in pidgin 2.10.6-3 (bookworm)2013
CVE-2013-0273 [MEDIUM] CVE-2013-0273: pidgin - sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 ... sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.10.6-3) bullseye: resolved (fixed in 2.10.6-3) forky: resolved (fixed in 2.10.6-3) sid: resolved (fixed
debian
CVE-2010-0423P4LOWCVSS 5.0fixed in pidgin 2.6.6-1 (bookworm)2010
CVE-2010-0423 [MEDIUM] CVE-2010-0423: pidgin - gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of ... gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat. Scope: local bookworm: resolved (fixed in 2.6.6-1) bullseye: resolved (fixed in 2.6.6-1) forky: resolved (fixed in 2.6.6-1) sid: resolved (fixed in 2.6.6-1) trixie: resolved (fixed in 2.6.6-1)
debian
CVE-2009-1375P4MEDIUMCVSS 5.0fixed in pidgin 2.5.6-1 (bookworm)2009
CVE-2009-1375 [MEDIUM] CVE-2009-1375: pidgin - The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does ... The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers to cause a denial of service (memory corruption and application crash) via vectors involving the (1) XMPP or (2) Sametime protocol. Scope: local bookworm: resolved (fixed in 2.5.6-1) bullseye: resolved (fixed in 2.5.6-1
debian
CVE-2013-6482P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6482 [MEDIUM] CVE-2013-6482: pidgin - Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NUL... Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2) OIM XML response, or (3) Content-Length header. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixed in 2.10.8-1) sid: resolved (fixed in 2.10.8-1) trixie: re
debian
CVE-2013-6484P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6484 [MEDIUM] CVE-2013-6484: pidgin - The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows rem... The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash) by triggering a socket read error. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixed in 2.10.8-1) sid: resolved (fixed in 2.1
debian
CVE-2013-6479P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6479 [MEDIUM] CVE-2013-6479: pidgin - util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory fo... util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denial of service (application crash) via a crafted response. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixe
debian
CVE-2011-3184P4LOWCVSS 4.3fixed in pidgin 2.10.0-1 (bookworm)2011
CVE-2011-3184 [MEDIUM] CVE-2011-3184: pidgin - The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in... The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message. Scope: local bookworm: resolved (fixed in 2.10.0-1) bu
debian
CVE-2014-3695P4MEDIUMCVSS 5.0fixed in pidgin 2.10.10-1 (bookworm)2014
CVE-2014-3695 [MEDIUM] CVE-2014-3695: pidgin - markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allow... markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response. Scope: local bookworm: resolved (fixed in 2.10.10-1) bullseye: resolved (fixed in 2.10.10-1) forky: resolved (fixed in 2.10.10-1) sid: resolved (fixed in 2.10.10-1) trixie:
debian
CVE-2014-0020P4MEDIUMCVSS 5.0fixed in pidgin 2.10.8-1 (bookworm)2014
CVE-2014-0020 [MEDIUM] CVE-2014-0020: pidgin - The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate a... The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (fixed in 2.10.8-1) sid: resolved (fixed in 2.10.8-1) trixie:
debian
CVE-2011-3594P4LOWCVSS 4.3fixed in pidgin 2.10.1-1 (bookworm)2011
CVE-2011-3594 [MEDIUM] CVE-2011-3594: pidgin - The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10... The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2. Scope: local book
debian
CVE-2010-3711P4MEDIUMCVSS 4.0fixed in pidgin 2.7.4-1 (bookworm)2010
CVE-2010-3711 [MEDIUM] CVE-2010-3711: pidgin - libpurple in Pidgin before 2.7.4 does not properly validate the return value of ... libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support. Scope: local boo
debian
Debian Pidgin vulnerabilities | cvebase