Логотип exploitDog
bind: "CVE-2022-26491"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-26491"

Количество 10

Количество 10

ubuntu логотип

CVE-2022-26491

почти 4 года назад

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-26491

почти 4 года назад

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-26491

почти 4 года назад

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2022-26491

почти 4 года назад

An issue was discovered in Pidgin before 2.14.9. A remote attacker who ...

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1693-1

почти 4 года назад

Security update for pidgin

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1665-1

почти 4 года назад

Security update for pidgin

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1664-1

почти 4 года назад

Security update for pidgin

EPSS: Низкий
github логотип

GHSA-4hw8-r3fw-2q2x

почти 4 года назад

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2025-03801

почти 4 года назад

Уязвимость системы мгновенного обмена сообщениями Pidgin, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю получить контроль над соединением XMPP, учетные данные пользователя и содержимое сообщений

CVSS3: 6.4
EPSS: Низкий
redos логотип

ROS-20250326-01

около 1 года назад

Уязвимость pidgin

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-26491

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

CVSS3: 5.9
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-26491

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

CVSS3: 6.4
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-26491

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

CVSS3: 5.9
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-26491

An issue was discovered in Pidgin before 2.14.9. A remote attacker who ...

CVSS3: 5.9
1%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:1693-1

Security update for pidgin

1%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:1665-1

Security update for pidgin

1%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:1664-1

Security update for pidgin

1%
Низкий
почти 4 года назад
github логотип
GHSA-4hw8-r3fw-2q2x

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

CVSS3: 5.9
1%
Низкий
почти 4 года назад
fstec логотип
BDU:2025-03801

Уязвимость системы мгновенного обмена сообщениями Pidgin, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю получить контроль над соединением XMPP, учетные данные пользователя и содержимое сообщений

CVSS3: 6.4
1%
Низкий
почти 4 года назад
redos логотип
ROS-20250326-01

Уязвимость pidgin

CVSS3: 5.9
1%
Низкий
около 1 года назад

Уязвимостей на страницу