Skip to main content

Vendor/product archive

rob_flynn / gaim CVEs

Beta · best-effort

26 CVEs tagged to rob_flynn / gaim2 Critical, 10 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2005-2102

Published Aug 16, 2005

The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2370

Published Jul 26, 2005

Multiple "memory alignment errors" in libgadu, as used in ekg before 1.6rc2, Gaim before 1.5.0, and other packages, allows remote attackers to cause a denial of service (bus error…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1269

Published Jun 16, 2005

Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1934

Published May 19, 2005

Gaim before 1.3.1 allows remote attackers to cause a denial of service (crash) via a malformed MSN message that leads to a memory allocation of a large size, possibly due to an in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1261

Published May 11, 2005

Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1262

Published May 11, 2005

Gaim 1.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed MSN message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0208

Published May 2, 2005

The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access,"…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0573

Published May 2, 2005

Gaim 1.1.3 on Windows systems allows remote attackers to cause a denial of service (client crash) via a file transfer in which the filename contains "(" or ")" (parenthesis) chara…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0965

Published May 2, 2005

The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contai…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0966

Published May 2, 2005

The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0967

Published May 2, 2005

Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2589

Published Dec 31, 2004

Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length header, which causes Gaim to abort when attempting to alloca…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0754

Published Oct 20, 2004

Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0784

Published Oct 20, 2004

The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0785

Published Oct 20, 2004

Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0006

Published Mar 3, 2004

Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0007

Published Mar 3, 2004

Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0008

Published Mar 3, 2004

Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0384

Published Oct 4, 2002

Buffer overflow in Jabber plug-in for Gaim client before 0.58 allows remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0989

Published Sep 24, 2002

The URL handler in the manual browser option for Gaim before 0.59.1 allows remote attackers to execute arbitrary script via shell metacharacters in a link.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0377

Published May 29, 2002

Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users w…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2