Bitlbee is a narrowly scoped instant-messaging gateway and relay application that bridges multiple chat protocols into a unified interface, with its vulnerability exposure concentrated in a single product line. Vulnerabilities affecting the vendor skew strongly toward critical severity, reflecting the memory-safety and privilege-management demands inherent in a protocol-translation daemon that handles untrusted network input and manages session privileges; the recurrent weakness classes include NULL-pointer dereferences, use-after-free conditions, and improper privilege-dropping logic. Defenders who deploy Bitlbee as an always-on relay or in shared-access scenarios should treat advisories as priority items; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bitlbee over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1187CRITICAL Bitlbee does not drop extra group privileges correctly in unix.c | Oct 29, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-5668CRITICAL bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer req | Mar 14, 2017 | 9.8 | 31 | NO | NO |
CVE-2016-10188CRITICAL Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfe | Mar 14, 2017 | 9.8 | 31 | NO | NO |
CVE-2016-10189HIGH BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a c | Mar 14, 2017 | 7.5 | 26 | NO | NO |
CVE-2008-3920HIGH Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors. | Sep 4, 2008 | 7.5 | 20 | NO | NO |
CVE-2008-3969MEDIUM Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handl | Sep 11, 2008 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bitlbee.
Media articles that mention a CVE ID that affects a product developed by Bitlbee — matched by CVE ID, not by vendor name.