Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-2371

Опубликовано: 06 янв. 2017
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*
Версия до 2.10.12 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03521
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 9 лет назад

An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.

CVSS3: 5.6
redhat
больше 9 лет назад

An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.

CVSS3: 8.1
debian
около 9 лет назад

An out-of-bounds write vulnerability exists in the handling of the MXI ...

CVSS3: 8.1
github
больше 3 лет назад

An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.

suse-cvrf
больше 9 лет назад

Security update for pidgin

EPSS

Процентиль: 87%
0.03521
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-787