cbcvebase.

Debian Pidgin vulnerabilities

80 known vulnerabilities affecting debian/pidgin.

Total CVEs
80
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM43LOW26

Vulnerabilities

Page 4 of 4
CVE-2016-4323P4LOWCVSS 3.7fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-4323 [LOW] CVE-2016-4323: pidgin - A directory traversal exists in the handling of the MXIT protocol in Pidgin. Spe... A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability. Scope: local bookworm: resolved (fixed in 2.11.0-
debian
CVE-2009-1889P4LOWCVSS 5.0fixed in pidgin 2.5.8-1 (bookworm)2009
CVE-2009-1889 [MEDIUM] CVE-2009-1889: pidgin - The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWe... The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory. Scope: local bookworm: resolved (fixed in 2.5.8-1) bullseye: resolved (fixed
debian
CVE-2009-3084P4LOWCVSS 5.0fixed in pidgin 2.6.2-1 (bookworm)2009
CVE-2009-3084 [MEDIUM] CVE-2009-3084: pidgin - The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN... The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name. Scope: local bookwor
debian
CVE-2012-2318P4MEDIUMCVSS 5.0fixed in pidgin 2.10.4-1 (bookworm)2012
CVE-2012-2318 [MEDIUM] CVE-2012-2318: pidgin - msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not p... msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message. Scope: local bookworm: resolved (fixed in 2.10.4-1) bullseye: resolved (fixed in 2.10.4-1) forky: resolved (fixed in 2.10.4-
debian
CVE-2009-3085P4LOWCVSS 5.0fixed in pidgin 2.6.2-1 (bookworm)2009
CVE-2009-3085 [MEDIUM] CVE-2009-3085: pidgin - The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly h... The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: reso
debian
CVE-2012-1178P4LOWCVSS 5.0fixed in pidgin 2.10.2-1 (bookworm)2012
CVE-2012-1178 [MEDIUM] CVE-2012-1178: pidgin - The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpu... The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial of service (application crash) via an OIM message that lacks UTF-8 encoding. Scope: local bookworm: resolved (fixed in 2.10.2-1) bullseye: resolved (fixed in 2.10.2-1) forky: resolved (fixed in 2.10.2-1) sid: resolved (f
debian
CVE-2013-6478P4MEDIUMCVSS 4.3fixed in pidgin 2.10.8-1 (bookworm)2013
CVE-2013-6478 [MEDIUM] CVE-2013-6478: pidgin - gtkimhtml.c in Pidgin before 2.10.8 does not properly interact with underlying l... gtkimhtml.c in Pidgin before 2.10.8 does not properly interact with underlying library support for wide Pango layouts, which allows user-assisted remote attackers to cause a denial of service (application crash) via a long URL that is examined with a tooltip. Scope: local bookworm: resolved (fixed in 2.10.8-1) bullseye: resolved (fixed in 2.10.8-1) forky: resolved (f
debian
CVE-2011-2943P4MEDIUMCVSS 4.3fixed in pidgin 2.10.0-1 (bookworm)2011
CVE-2011-2943 [MEDIUM] CVE-2011-2943: pidgin - The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0... The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response. Scope
debian
CVE-2009-2703P4LOWCVSS 5.0fixed in pidgin 2.6.2 (bookworm)2009
CVE-2009-2703 [MEDIUM] CVE-2009-2703: pidgin - libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin... libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string. Scope: local bookworm: resolved (fixed in 2.6.2) bullseye: resolved (fixed in 2.6.2) forky: resolved (fixed in 2.6.2) sid: r
debian
CVE-2010-0420P4LOWCVSS 4.3fixed in pidgin 2.6.6-1 (bookworm)2010
CVE-2010-0420 [MEDIUM] CVE-2010-0420: pidgin - libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) ro... libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname. Scope: local bookworm: resolved (fixed in 2.6.6-1) bullseye: resolved (fixed in 2.6.6-1) forky: resolved (fixed in 2.6
debian
CVE-2009-3025P4LOWCVSS 4.3fixed in pidgin 2.6.1-1 (bookworm)2009
CVE-2009-3025 [MEDIUM] CVE-2009-3025: pidgin - Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a den... Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM. Scope: local bookworm: resolved (fixed in 2.6.1-1) bullseye: resolved (fixed in 2.6.1-1) forky: resolved (fixed in 2.6.1-1) sid: resolved (fixed in 2.6.1-1) trixie: resolved (fixed in 2.6.1-1)
debian
CVE-2011-1091P4LOWCVSS 4.0fixed in pidgin 2.7.11-1 (bookworm)2011
CVE-2011-1091 [MEDIUM] CVE-2011-1091: pidgin - libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7... libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malfor
debian
CVE-2007-4996P4MEDIUMCVSS 4.3fixed in pidgin 2.2.1-1 (bookworm)2007
CVE-2007-4996 [MEDIUM] CVE-2007-4996: pidgin - libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages fro... libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location." Scope: local bookworm: resolved (fixed in 2.2.1-1) bullseye: resolved (fixed in 2.2.1-1) forky:
debian
CVE-2010-4528P4MEDIUMCVSS 4.0fixed in pidgin 2.7.9-1 (bookworm)2010
CVE-2010-4528 [MEDIUM] CVE-2010-4528: pidgin - directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidg... directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a short p2pv2 packet in a DirectConnect (aka direct connection) session. Scope: local bookworm: resolved (fixed in 2.7.9-1) bullseye: resolved (fixed in 2.7.
debian
CVE-2010-2528P4MEDIUMCVSS 4.0fixed in pidgin 2.7.2-1 (bookworm)2010
CVE-2010-2528 [MEDIUM] CVE-2010-2528: pidgin - The clientautoresp function in family_icbm.c in the oscar protocol plugin in lib... The clientautoresp function in family_icbm.c in the oscar protocol plugin in libpurple in Pidgin before 2.7.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via an X-Status message that lacks the expected end tag for a (1) desc or (2) title element. Scope: local bookworm: resolved (fixed in 2.7.2-1) bul
debian
CVE-2016-2380P4LOWCVSS 3.1fixed in pidgin 2.11.0-1 (bookworm)2016
CVE-2016-2380 [LOW] CVE-2016-2380: pidgin - An information leak exists in the handling of the MXIT protocol in Pidgin. Speci... An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read. Scope: local bookworm: resolved (fixed in 2.11.0-1)
debian
CVE-2007-4999P4MEDIUMCVSS 4.3fixed in pidgin 2.2.2-1 (bookworm)2007
CVE-2007-4999 [MEDIUM] CVE-2007-4999: pidgin - libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote ... libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996. Scope: local bookworm: resolved (fixed in 2.2.2-1) bullseye: resolved (fixed in 2.2.2-1) forky: resolved (fixed in 2.2.2-1)
debian
CVE-2012-2214P4LOWCVSS 3.5fixed in pidgin 2.10.4-1 (bookworm)2012
CVE-2012-2214 [LOW] CVE-2012-2214: pidgin - proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled S... proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests. Scope: local bookworm: resolved (fixed in 2.10.4-1) bullseye: resolved (fixed in 2.10.4-1) forky: resolved (fixed i
debian
CVE-2013-0274P4LOWCVSS 2.9fixed in pidgin 2.10.6-3 (bookworm)2013
CVE-2013-0274 [LOW] CVE-2013-0274: pidgin - upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long str... upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network. Scope: local bookworm: resolved (fixed in 2.10.6-3) bullseye: resolved (fixed in 2.10.6-3) forky: resolved (fixed in 2.10.6-3) sid: resolved (fixe
debian
CVE-2011-4922P4LOWCVSS 2.1fixed in pidgin 2.7.11-1 (bookworm)2011
CVE-2011-4922 [LOW] CVE-2011-4922: pidgin - cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encrypti... cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents. Scope: local bookworm: resolved (fixed in 2.7.11-1) bullseye: resolved (fixed in 2.7.11-1) forky: resolved (fixed in 2.7.11-1) sid:
debian
Debian Pidgin vulnerabilities | cvebase