|
284501
|
- |
|
pidgin
|
pidgin
|
gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: URL that is improperly handled during construction o…
|
CWE-20
Improper Input Validation
|
CVE-2013-6486
|
2024-11-21 10:59 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284502
|
- |
|
pidgin
|
pidgin
|
Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid chu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-6485
|
2024-11-21 10:59 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284503
|
- |
|
pidgin
|
pidgin
|
The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash) by triggering a soc…
|
CWE-20
Improper Input Validation
|
CVE-2013-6484
|
2024-11-21 10:59 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284504
|
- |
|
pidgin
|
pidgin
|
The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remo…
|
CWE-20
Improper Input Validation
|
CVE-2013-6483
|
2024-11-21 10:59 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284505
|
- |
|
pidgin
|
pidgin
|
util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a deni…
|
CWE-399
Resource Management Errors
|
CVE-2013-6479
|
2024-11-21 10:59 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284506
|
- |
|
pidgin
|
pidgin
|
gtkimhtml.c in Pidgin before 2.10.8 does not properly interact with underlying library support for wide Pango layouts, which allows user-assisted remote attackers to cause a denial of service (applic…
|
CWE-20
Improper Input Validation
|
CVE-2013-6478
|
2024-11-21 10:59 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284507
|
- |
|
pidgin
|
pidgin
|
Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a crafted timestamp value in an XMPP message.
|
CWE-189
Numeric Errors
|
CVE-2013-6477
|
2024-11-21 10:59 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284508
|
- |
|
openstack redhat
|
oslo openstack
|
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive i…
|
CWE-310
Cryptographic Issues
|
CVE-2013-6491
|
2024-11-21 10:59 |
2014-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284509
|
- |
|
ibm
|
spss_samplepower
|
Unspecified vulnerability in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 IF1 allows remote attackers to execute arbitrary code via a crafted ComboList property value.
|
NVD-CWE-noinfo
|
CVE-2013-6724
|
2024-11-21 10:59 |
2014-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284510
|
- |
|
ibm
|
sametime
|
The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote attackers to obtain sensitive information via unspeci…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6727
|
2024-11-21 10:59 |
2014-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|