VYPR
Vendor

Bitlbee

Products
2
CVEs
6
Across products
8
Status
Private

Products

2

Recent CVEs

6
  • CVE-2017-5668CriMar 14, 2017
    risk 0.64cvss 9.8epss 0.03

    bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerability exists because of an…

  • CVE-2016-10188CriMar 14, 2017
    risk 0.64cvss 9.8epss 0.03

    Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to expire.

  • CVE-2016-10189HigMar 14, 2017
    risk 0.42cvss 7.5epss 0.04

    BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list.

  • CVE-2012-1187Oct 29, 2019
    risk 0.00cvss epss 0.02

    Bitlbee does not drop extra group privileges correctly in unix.c

  • CVE-2008-3969Sep 11, 2008
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because of an incomplete fix for…

  • CVE-2008-3920Sep 4, 2008
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors.