Kadu is an instant-messaging and communication platform with a focused vulnerability profile concentrated in its single-product codebase. The observed weakness classes center on cross-site scripting and input-handling issues characteristic of web-facing communication applications, with current severity and exploitation counts shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kadu over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1852HIGH Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a | Jul 26, 2005 | 7.5 | 21 | NO | NO |
CVE-2005-3960HIGH Kadu 0.4.2 and 0.5.0pre allows remote attackers to cause a denial of service (crash or generated traffic) via a malformed message, possibly with incomplete information. | Dec 1, 2005 | 7.8 | 20 | NO | NO |
CVE-2012-1410MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the History Window implementation in Kadu 0.9.0 through 0.11.0 allow remote attackers to inject arbitrary web script or HTML | Feb 29, 2012 | 4.3 | 18 | NO | NO |
CVE-2006-0768MEDIUM Kadu 0.4.3 allows remote attackers to cause a denial of service (application crash) via a large number of image send requests. | Feb 18, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kadu.
Media articles that mention a CVE ID that affects a product developed by Kadu — matched by CVE ID, not by vendor name.