PGP's vulnerability footprint centers on a focused line of encryption and data-protection products spanning personal, corporate, and desktop variants, positioned as privacy and secure-communication tools across consumer and enterprise markets. While the vendor maintains a modestly represented disclosure volume, its products have an elevated tendency to acquire public exploit code, reflecting the appeal of encryption software as a target for security research and tool development. The recurring weakness classes—incomplete cleanup, cleartext storage of sensitive information, improper input validation, and memory-buffer issues—point to credential-handling and cryptographic-material management as durable exposure points across the portfolio. Defenders should prioritize inventory of deployed PGP versions given the sensitivity of encrypted data and key material at risk; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pgp over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-1320HIGH Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer | Jul 16, 2001 | 7.5 | 75 | NO | YES |
CVE-2010-3397HIGH Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local users, and possibly remote attackers, to exe | Sep 15, 2010 | 9.3 | 28 | NO | NO |
CVE-2002-0685HIGH Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freewar | Jul 23, 2002 | 7.5 | 25 | NO | NO |
CVE-2001-1252HIGH Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of k | Sep 28, 2001 | 10.0 | 25 | NO | NO |
CVE-2008-5731MEDIUM The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause a denial of service (system crash) and p | Dec 26, 2008 | 4.9 | 22 | NO | YES |
CVE-2001-1456HIGH Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message. | Sep 4, 2001 | 7.5 | 21 | NO | NO |
CVE-2007-0603HIGH PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, wh | Jan 30, 2007 | 7.1 | 20 | NO | NO |
CVE-2002-1696MEDIUM Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" opti | Dec 31, 2002 | 5.5 | 20 | NO | NO |
CVE-2002-2069HIGH PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supp | Dec 31, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-0850HIGH Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long filename when it is decrypted. | Oct 4, 2002 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pgp.
Media articles that mention a CVE ID that affects a product developed by Pgp — matched by CVE ID, not by vendor name.