Pidgin is a widely deployed open-source instant-messaging client and its underlying libpurple library that consolidates multiple chat protocols into a single application, positioning it as a critical component in the messaging supply chain despite a narrow product portfolio. Vulnerabilities affecting the vendor recur through input-validation and memory-safety weakness classes—including improper input validation, buffer-boundary violations, and out-of-bounds reads—that are characteristic of protocol parsing in a multi-protocol abstraction layer. The exposure also includes instances of sensitive-information disclosure, reflecting the complexity of handling credentials and session state across heterogeneous messaging backends. A moderate tendency toward public exploit availability underscores the appeal of messaging clients as targets for credential theft and code execution, and defenders should treat Pidgin updates as important for desktop and embedded deployments where the client sees use. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pidgin over time
Signals from CVEs in this vendor scope (91 CVEs).
91 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2694HIGH The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote at | Aug 21, 2009 | 10.0 | 52 | NO | YES |
CVE-2010-0013HIGH Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot | Jan 9, 2010 | 7.5 | 40 | NO | YES |
CVE-2009-1376HIGH Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c | May 26, 2009 | 9.3 | 39 | NO | YES |
CVE-2013-6490HIGH The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header, which triggers a buffer overfl | Feb 6, 2014 | 10.0 | 37 | NO | NO |
CVE-2017-2640CRITICAL An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute ar | Jul 27, 2018 | 9.8 | 34 | NO | NO |
CVE-2016-1000030CRITICAL Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_im | Sep 5, 2018 | 9.8 | 31 | NO | NO |
CVE-2009-2404HIGH Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, a | Aug 3, 2009 | 9.3 | 31 | NO | NO |
CVE-2012-1257MEDIUM Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor. | Nov 20, 2019 | 5.5 | 29 | NO | YES |
CVE-2016-2379HIGH The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration co | Mar 29, 2017 | 8.8 | 28 | NO | NO |
CVE-2011-3185HIGH gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message. | Aug 29, 2011 | 9.3 | 28 | NO | NO |
Signals from CVEs in this vendor scope (91 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pidgin.
Media articles that mention a CVE ID that affects a product developed by Pidgin — matched by CVE ID, not by vendor name.