Pidgin 是支持多种协议的即时通讯客户端。 Pidgin 2.7.4之前版本中的libpurple不能正确校验purple_base64_decode函数的返回值。远程认证用户可以借助特制消息导致拒绝服务(空指针解引用以及应用程序崩溃)。该漏洞与MSN,MySpaceIM,XMPP,Yahoo!以及NTLM认证支持的插件有关。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2010-2891 | libsmi lib/smi.c文件smiGetNode函数缓冲区溢出漏洞 | |
| CVE-2010-3712 | Joomla!多个跨站脚本攻击漏洞 | |
| CVE-2010-3713 | UseBB rss.php文件权限许可和访问控制漏洞 | |
| CVE-2010-3765 | Mozilla Firefox/Thunderbird/SeaMonkey JavaScript缓冲区溢出漏洞 | |
| CVE-2010-3842 | curl Content-disposition HTTP绝对路径遍历漏洞 | |
| CVE-2010-3933 | Ruby on Rails输入验证漏洞 | |
| CVE-2010-4096 | Monkeysphere 'share/ma/keys_for_user'代码注入漏洞 | |
| CVE-2010-4097 | Avatic Aardvark Topsites PHP index.php文件多个跨站脚本攻击漏洞 | |
| CVE-2010-4098 | monotone设计错误漏洞 | |
| CVE-2010-4099 | NitroSecurity NitroView ESM ess.pm文件输入验证漏洞 |
No comments yet