Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pidgin

First CVE: Jul 17, 2007Active for: 19 yearsTotal CVEs: 91
33.3
VTI Score
Medium

Pidgin is a widely deployed open-source instant-messaging client and its underlying libpurple library that consolidates multiple chat protocols into a single application, positioning it as a critical component in the messaging supply chain despite a narrow product portfolio. Vulnerabilities affecting the vendor recur through input-validation and memory-safety weakness classes—including improper input validation, buffer-boundary violations, and out-of-bounds reads—that are characteristic of protocol parsing in a multi-protocol abstraction layer. The exposure also includes instances of sensitive-information disclosure, reflecting the complexity of handling credentials and session state across heterogeneous messaging backends. A moderate tendency toward public exploit availability underscores the appeal of messaging clients as targets for credential theft and code execution, and defenders should treat Pidgin updates as important for desktop and embedded deployments where the client sees use. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
91
Total CVEs
More Total CVEs than 99% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pidgin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2007
19 years ago
Most Recent CVE
Mar 21, 2026
125 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (91 CVEs).

91 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-2694HIGH
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote at
Aug 21, 200910.052NOYES
CVE-2010-0013HIGH
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot
Jan 9, 20107.540NOYES
CVE-2009-1376HIGH
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c
May 26, 20099.339NOYES
CVE-2013-6490HIGH
The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header, which triggers a buffer overfl
Feb 6, 201410.037NONO
CVE-2017-2640CRITICAL
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute ar
Jul 27, 20189.834NONO
CVE-2016-1000030CRITICAL
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_im
Sep 5, 20189.831NONO
CVE-2009-2404HIGH
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, a
Aug 3, 20099.331NONO
CVE-2012-1257MEDIUM
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
Nov 20, 20195.529NOYES
CVE-2016-2379HIGH
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration co
Mar 29, 20178.828NONO
CVE-2011-3185HIGH
gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.
Aug 29, 20119.328NONO
View all 91 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products91 CVEs
71%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.2%)
Network20 (22.0%)
Unknown68 (74.7%)
Physical0 (0.0%)
Adjacent Network1 (1.1%)
Attack Complexity
Low7 (7.7%)
High16 (17.6%)
Unknown68 (74.7%)
User Interaction
None22 (24.2%)
Unknown68 (74.7%)
Required1 (1.1%)
Privileges Required
Low2 (2.2%)
High0 (0.0%)
None21 (23.1%)
Unknown68 (74.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (91 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
5.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pidgin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pidgin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pidgin's Products

View all 4 CNAs →

Top CWEs