LIVE NEWSROOM · --:-- · May 30, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2008-6393

CVE-2008-6393

CVSS 10 · HIGH

Summary

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.

CVSS 2.0 breakdown

Base score10 (HIGH)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Attack vectorNETWORK
Attack complexityLOW
ConfidentialityCOMPLETE
IntegrityCOMPLETE
AvailabilityCOMPLETE

Weakness type (CWE)

Affected products

Psi-im psiJabber jabber client
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-23. Always verify against the vendor advisory before acting.

Scroll to Top