Getfiregpg's vulnerability footprint centers on its Firefox-integrated email encryption plugin, with exposure concentrated around sensitive-data handling and file-system access patterns endemic to browser-based cryptographic tools. The recurring weakness classes—cleartext storage of sensitive information and improper link resolution before file access—reflect the inherent tension between managing cryptographic material in a browser environment and secure interaction with the underlying file system. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getfiregpg over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7273HIGH A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling. | Nov 18, 2019 | 7.8 | 25 | NO | NO |
CVE-2008-7272HIGH FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromi | Nov 8, 2019 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getfiregpg.
Media articles that mention a CVE ID that affects a product developed by Getfiregpg — matched by CVE ID, not by vendor name.