CVE-2011-3635
Empathy <3.2.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname).
References (7)
Scores
EPSS
0.0048
EPSS Percentile
64.8%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
gnome/empathy
< 3.2.1
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
gnome/empathy
... and 35 more
Timeline
Published
Oct 23, 2011
Tracked Since
Feb 18, 2026