Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-0013

40
FAUCET Score

CVE-2010-0013 is a directory traversal vulnerability in the MSN protocol plugin of Pidgin 2.6.4 and Adium 1.3.8, allowing remote attackers to read arbitrary files. This high-severity vulnerability (CVSS 7.5) can be exploited with low complexity over the network, potentially leading to unauthorized information disclosure. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry (EDB-11203) exists, and the CVE has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.3.8CPE matchmatch criteria
cpe:2.3:a:adium:adium:1.3.8:*:*:*:*:*:*:*
2.6.4CPE matchmatch criteria
cpe:2.3:a:pidgin:pidgin:2.6.4:*:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*
12CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*
>= 11.0, <= 11.2CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
12.50%
Probability of exploitation in next 30 days
EPSS Percentile
95.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-11203 · Jan 19, 2010
This CVE's current EPSS score of 0.1250 is in the 94th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: pidgin-0:2.6.5-1.el4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: pidgin-0:2.6.5-1.el5
View patch

Vendor Advisories (1)

redhatCVE-2010-0013Important

pidgin/libpurple: MSN custom smiley request directory traversal file disclosure

Dec 27, 2009

References

developer.pidgin.im / viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.c
Broken Link
d.pidgin.im / viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467
Broken Link
d.pidgin.im / viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92f
Broken Link
d.pidgin.im / viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810
Broken Link
events.ccc.de / congress/2009/Fahrplan/events/3596.en.html
Product
lists.fedoraproject.org / pipermail/package-announce/2010-January/033771.html
Mailing List
lists.fedoraproject.org / pipermail/package-announce/2010-January/033848.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2010-03/msg00004.html
Mailing List
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatch
secunia.com / advisories/37953
Broken LinkVendor Advisory
secunia.com / advisories/37954
Broken LinkVendor Advisory
secunia.com / advisories/37961
Broken Link
secunia.com / advisories/38915
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10333
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17620
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
mandriva.com / security/advisories
Broken Link
openwall.com / lists/oss-security/2010/01/02/1
Mailing ListPatch
openwall.com / lists/oss-security/2010/01/07/1
Mailing List
openwall.com / lists/oss-security/2010/01/07/2
Mailing List
vupen.com / english/advisories/2009/3662
Permissions RequiredVendor Advisory
vupen.com / english/advisories/2009/3663
Permissions RequiredVendor Advisory
vupen.com / english/advisories/2010/1020
Permissions Required