258341
|
- |
|
pidgin
|
pidgin
|
libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (crash) via a Yahoo! P2P message with a crafted length field, which triggers a buffer …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-6481
|
2014-03-16 13:42 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258342
|
- |
|
pidgin
|
pidgin
|
Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2) OIM XML response, or (3) Content-Length header.
|
CWE-20
Improper Input Validation
|
CVE-2013-6482
|
2014-03-16 13:42 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258343
|
- |
|
pidgin
|
pidgin
|
The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remo…
|
CWE-20
Improper Input Validation
|
CVE-2013-6483
|
2014-03-16 13:42 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258344
|
- |
|
pidgin
|
pidgin
|
The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash) by triggering a soc…
|
CWE-20
Improper Input Validation
|
CVE-2013-6484
|
2014-03-16 13:42 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258345
|
- |
|
pidgin
|
pidgin
|
Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid chu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-6485
|
2014-03-16 13:42 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258346
|
- |
|
pidgin
|
pidgin
|
gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: URL that is improperly handled during construction o…
|
CWE-20
Improper Input Validation
|
CVE-2013-6486
|
2014-03-16 13:42 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258347
|
- |
|
redhat
|
icedtea-web
|
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a tem…
|
CWE-200
Information Exposure
|
CVE-2013-6493
|
2014-03-16 13:42 |
2014-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258348
|
- |
|
linux
|
linux_kernel
|
The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a …
|
CWE-310
Cryptographic Issues
|
CVE-2013-4579
|
2014-03-16 13:39 |
2013-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258349
|
- |
|
apple
|
iphone_os
|
Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger in…
|
CWE-20
Improper Input Validation
|
CVE-2013-3948
|
2014-03-16 13:38 |
2013-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258350
|
- |
|
oracle
|
enterprise_manager_database_control enterprise_manager_grid_control
|
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5, and EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3, al…
|
NVD-CWE-noinfo
|
CVE-2013-0354
|
2014-03-16 13:33 |
2013-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|