Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-1769 | 1 Simon Mcvittie | 1 Telepathy Gabble | 2024-02-04 | 5.0 MEDIUM | N/A |
A certain hashing algorithm in Telepathy Gabble 0.16.x before 0.16.5 and 0.17.x before 0.17.3 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted message. | |||||
CVE-2013-1431 | 1 Simon Mcvittie | 1 Telepathy Gabble | 2024-02-04 | 6.8 MEDIUM | N/A |
The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks. |