Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    5
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-39835

    An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat. The fixed version is 1.5.0.

    Last Modified: May 21, 2025
    Published: Sep 27, 2022

    CVE-2021-41055

    Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID.

    Last Modified: Nov 21, 2024
    Published: Oct 11, 2021

    CVE-2016-10376

    Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

    Last Modified: Apr 20, 2025
    Published: May 28, 2017

    CVE-2015-8688

    Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.

    Last Modified: Apr 12, 2025
    Published: Jan 15, 2016

    CVE-2012-5524

    The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA.

    Last Modified: Apr 11, 2025
    Published: Feb 08, 2014
    Items Per Page
    Gajim Vulnerabilities & Security CVEs | CVE-DB