Adium is a modestly represented instant-messaging client whose vulnerability footprint concentrates in a single, widely used cross-platform application. The durable signal centers on path-traversal and file-handling weaknesses characteristic of desktop messaging software, though public exploit tooling has been available for reported issues. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adium over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2694HIGH The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote at | Aug 21, 2009 | 10.0 | 52 | NO | YES |
CVE-2010-0013HIGH Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot | Jan 9, 2010 | 7.5 | 40 | NO | YES |
CVE-2008-7190HIGH Unspecified vulnerability in Adium before 1.2 has unknown impact and attack vectors related to javascript: URLs, possibly cross-site scripting (XSS). | Sep 9, 2009 | 10.0 | 24 | NO | NO |
CVE-2010-0277MEDIUM slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and a | Jan 9, 2010 | 5.0 | 20 | NO | NO |
CVE-2009-3615MEDIUM The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-li | Oct 20, 2009 | 5.0 | 20 | NO | NO |
CVE-2008-2927MEDIUM Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c | Jul 7, 2008 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adium.
Media articles that mention a CVE ID that affects a product developed by Adium — matched by CVE ID, not by vendor name.