Libpurple
Vendor:
First CVE: Sep 8, 2009 · Active for 16 years
7
Total CVEs
More Total CVEs than 83% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
4.7
Avg CVSS
Higher Avg CVSS than 6% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libpurple over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 8, 2009
16 years ago
Most Recent CVE
Nov 4, 2011
5,376 days ago
CVE Severity & Scoring
Libpurple7 CVEs
100%
All CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3594MEDIUM The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a de | Nov 4, 2011 | 4.3 | 18 | NO | NO |
CVE-2010-4528MEDIUM directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer derefer | Jan 7, 2011 | 4.0 | 18 | NO | NO |
CVE-2011-2943MEDIUM The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which all | Aug 29, 2011 | 4.3 | 17 | NO | NO |
CVE-2009-3084MEDIUM The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attacke | Sep 8, 2009 | 5.0 | 17 | NO | NO |
CVE-2009-3083MEDIUM The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service ( | Sep 8, 2009 | 5.0 | 17 | NO | NO |
CVE-2009-3085MEDIUM The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers | Sep 8, 2009 | 5.0 | 16 | NO | NO |
CVE-2009-2703MEDIUM libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and a | Sep 8, 2009 | 5.0 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Libpurple
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.9.0 | 2 | 4.3 | 3.4% | 0 | 0 |
| 2.8.0 | 2 | 4.3 | 3.4% | 0 | 0 |
| 2.7.9 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.7.8 | 2 | 4.2 | 2.9% | 0 | 0 |
| 2.7.7 | 2 | 4.2 | 2.9% | 0 | 0 |
| 2.7.6 | 2 | 4.2 | 2.9% | 0 | 0 |
| 2.7.5 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.7.4 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.7.3 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.7.2 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.7.11 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.7.10 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.7.1 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.7.0 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.6.6 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.6.5 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.6.4 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.6.3 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.6.2 | 1 | 4.3 | 3.2% | 0 | 0 |
| 2.6.1 | 2 | 4.7 | 2.9% | 0 | 0 |