CVE-2011-4170 - CVE House
Back to Database
Status published Medium CVE-2011-4170

Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname) in a /me event, a different vulnerability than CVE-2011-3635.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-4170

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

empathy
Vulnerable Versions:
0, 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9, 0.11, 0.12, 0.13, 0.14, 0.21.1, 0.21.2, 0.21.3, 0.21.4, 0.21.5, 0.21.5.1, 0.21.5.2, 0.21.90, 0.21.91, 0.22.0, 0.22.1, 0.23.1, 0.23.2, 0.23.3, 0.23.4, 2.23.6, 2.23.90, 2.23.91, 2.23.92, 2.24.0, 2.24.1, 2.25.2, 2.25.3, 2.25.4, 2.25.90, 2.25.91, 2.25.92, 2.26.0, 2.26.0.1, 2.26.1, 2.26.2, 2.27.1, 2.27.1.1, 2.27.2, 2.27.3, 2.27.4, 2.27.5, 2.27.91, 2.27.91.1, 2.27.92, 2.28.0, 2.28.0.1, 2.28.1, 2.28.1.1, 2.28.1.2, 2.28.2, 2.29.1, 2.29.2, 2.29.3, 2.29.4, 2.29.5, 2.29.5.1, 2.29.6, 2.29.90, 2.29.91, 2.29.91.1, 2.29.91.2, 2.29.92, 2.29.93, 2.30.0, 2.30.0.1, 2.30.0.2, 2.30.1, 2.30.1.1, 2.30.2, 2.30.3, 2.31.1, 2.31.2, 2.31.3, 2.31.4, 2.31.5, 2.31.5.1, 2.31.6, 2.31.90, 2.31.91, 2.31.92, 2.32.0, 2.32.0.1, 2.32.1, 2.32.2, 2.33.1, 2.33.2, 2.33.3, 2.33.4, 2.34.0, 2.91.0, 2.91.1, 2.91.2, 2.91.3, 2.91.3.1, 2.91.4, 2.91.4.1, 2.91.4.2, 2.91.4.3, 2.91.5, 2.91.5.1, 2.91.6, 2.91.6.1, 2.91.90, 2.91.90.1, 2.91.90.2, 2.91.91, 2.91.91.1, 2.91.92, 2.91.93, 3.0.0, 3.0.1, 3.0.2, 3.1.1, 3.1.2, 3.1.2.1, 3.1.3, 3.1.4, 3.1.5, 3.1.5.1, 3.1.90, 3.1.90.1, 3.1.91, 3.1.92, 3.2.0.1

Timeline

Official Publish: October 23rd, 2011
Last Modified: September 16th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.