VendorsGadu-gadugadu-gadu_instant_messengerany version
Vulnerabilities

Gadu-gadu Gadu-gadu Instant Messenger any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2004-1232
Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename.
Published 2004-12-15 · Modified
10.0EPSS 0.062
CVE-2004-1229
Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410.
Published 2004-12-15 · Modified
7.5EPSS 0.016
CVE-2004-1231
Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequences in a DCC connection with a CTCP packet that contains a 1 as the type and a 4 as the subtype.
Published 2004-12-15 · Modified
5.0EPSS 0.017
CVE-2004-1233
Integer overflow in Gadu-Gadu allows remote attackers to cause a denial of service (disk consumption) via a user packet to the DCC file transfer capability with an invalid file length.
Published 2004-12-15 · Modified
5.0EPSS 0.016
CVE-2004-1230
Gadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CTCP packet that contains a 1 as the type and a 4 as the subtype.
Published 2004-12-15 · Modified
5.0EPSS 0.014
CVE-2007-6409
The gg protocol handler in Gadu-Gadu, when this product is installed but not running, does not properly handle the skin attribute, which allows remote attackers to cause a denial of service (resource consumption) via unspecified network traffic.
Published 2007-12-17 · Modified
4.3EPSS 0.010
CVE-2007-6410
Gadu-Gadu does not properly perform protocol handling, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and add arbitrary user accounts or cause a denial of service as administrators via an unspecified "crafted link," possibly related to the gg protocol.
Published 2007-12-17 · Modified
4.3EPSS 0.004
CVE-2004-2530
Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.
Published 2005-10-25 · Modified
2.61 PoCEPSS 0.020