Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pgp

First CVE: May 24, 2000Active for: 26 yearsTotal CVEs: 23
36.5
VTI Score
Medium

PGP's vulnerability footprint centers on a focused line of encryption and data-protection products spanning personal, corporate, and desktop variants, positioned as privacy and secure-communication tools across consumer and enterprise markets. While the vendor maintains a modestly represented disclosure volume, its products have an elevated tendency to acquire public exploit code, reflecting the appeal of encryption software as a target for security research and tool development. The recurring weakness classes—incomplete cleanup, cleartext storage of sensitive information, improper input validation, and memory-buffer issues—point to credential-handling and cryptographic-material management as durable exposure points across the portfolio. Defenders should prioritize inventory of deployed PGP versions given the sensitivity of encrypted data and key material at risk; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pgp over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2000
26 years ago
Most Recent CVE
Nov 22, 2010
5,723 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2001-1320HIGH
Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer
Jul 16, 20017.575NOYES
CVE-2010-3397HIGH
Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local users, and possibly remote attackers, to exe
Sep 15, 20109.328NONO
CVE-2002-0685HIGH
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freewar
Jul 23, 20027.525NONO
CVE-2001-1252HIGH
Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of k
Sep 28, 200110.025NONO
CVE-2008-5731MEDIUM
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause a denial of service (system crash) and p
Dec 26, 20084.922NOYES
CVE-2001-1456HIGH
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.
Sep 4, 20017.521NONO
CVE-2007-0603HIGH
PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, wh
Jan 30, 20077.120NONO
CVE-2002-1696MEDIUM
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" opti
Dec 31, 20025.520NONO
CVE-2002-2069HIGH
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supp
Dec 31, 20027.520NONO
CVE-2002-0850HIGH
Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long filename when it is decrypted.
Oct 4, 20027.520NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
22%
35%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (8.7%)
Network1 (4.3%)
Unknown20 (87.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (13.0%)
High0 (0.0%)
Unknown20 (87.0%)
User Interaction
None3 (13.0%)
Unknown20 (87.0%)
Required0 (0.0%)
Privileges Required
Low2 (8.7%)
High0 (0.0%)
None1 (4.3%)
Unknown20 (87.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pgp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pgp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pgp's Products

View all 2 CNAs →

Top CWEs