Libpurple

Vendor:

First CVE: Sep 8, 2009 · Active for 16 years

7
Total CVEs
More Total CVEs than 83% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
4.7
Avg CVSS
Higher Avg CVSS than 6% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libpurple over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 8, 2009
16 years ago
Most Recent CVE
Nov 4, 2011
5,376 days ago

CVE Severity & Scoring

Libpurple7 CVEs
All CVEs352,231 CVEs
Medium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a de
Nov 4, 20114.318NONO
directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer derefer
Jan 7, 20114.018NONO
The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which all
Aug 29, 20114.317NONO
The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attacke
Sep 8, 20095.017NONO
The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (
Sep 8, 20095.017NONO
The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers
Sep 8, 20095.016NONO
libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and a
Sep 8, 20095.016NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Libpurple

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.9.024.33.4%00
2.8.024.33.4%00
2.7.914.33.2%00
2.7.824.22.9%00
2.7.724.22.9%00
2.7.624.22.9%00
2.7.514.33.2%00
2.7.414.33.2%00
2.7.314.33.2%00
2.7.214.33.2%00
2.7.1114.33.2%00
2.7.1014.33.2%00
2.7.114.33.2%00
2.7.014.33.2%00
2.6.614.33.2%00
2.6.514.33.2%00
2.6.414.33.2%00
2.6.314.33.2%00
2.6.214.33.2%00
2.6.124.72.9%00