CVE-2014-3696 on Ubuntu 12.04 LTS (precise) - medium.
Description:
nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a crafted server message that triggers a large memory allocation.