CVE-2013-6486 PUBLISHED CVSS 9.300000190734863 CRITICAL

gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: URL that is improperly handled during construction of an explorer.exe command. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3185.

EPSS 1.27% · 79.4th percentile

Risk Scores

CVSS v2.0
9.300000190734863
EPSS Score
1.27%
79.4th percentile

Affected Products

VendorProductVersions
pidginpidgin2.10.6, 0, 2.0.0
n/an/an/a

Timeline

References

Open in Interactive Console →