pgp records
23 published records for vendor pgp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 4.3%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-459 Incomplete Cleanup2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-310 Cryptographic Issues1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2001-1320Weaponized | Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via expgp · keyserver | High7.5 | — | 68.3% | Jul 16, 2001 |
41Plan | CVE-2001-1252No exploit | Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs tpgp · keyserver | Critical10.0 | — | 3.2% | Sep 28, 2001 |
38Monitor | CVE-2010-3397No exploit | Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local userpgp · desktop | Critical9.3 | — | 4.2% | Sep 15, 2010 |
32Monitor | CVE-2001-1456No exploit | Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitramcafee · webshield smtp · CWE-119 | High7.5 | — | 5.7% | Sep 4, 2001 |
31Monitor | CVE-2002-0850No exploit | Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long fpgp · corporate desktop | High7.5 | — | 3.2% | Oct 4, 2002 |
31Monitor | CVE-2002-0685No exploit | Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0pgp · desktop security | High7.5 | — | 2.6% | Jul 23, 2002 |
31Monitor | CVE-2002-2069No exploit | PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recpgp · personal privacy · CWE-459 | High7.5 | — | 2.1% | Dec 31, 2002 |
30Monitor | CVE-2007-0603No exploit | PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpspgp · corporate desktop | High7.1 | — | 5.2% | Jan 30, 2007 |
30Monitor | CVE-2001-1016No exploit | PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly pgp · corporate desktop | High7.5 | — | 1.4% | Sep 4, 2001 |
28Monitor | CVE-2009-0681No exploit | PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) causpgp · desktop · CWE-20 | High7.2 | — | 0.4% | Apr 15, 2009 |
22Monitor | CVE-2002-0788No exploit | An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartextpgp · corporate desktop · CWE-459 | Medium5.5 | — | 0.4% | Aug 12, 2002 |
22Monitor | CVE-2002-1696No exploit | Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically depgp · personal privacy · CWE-312 | Medium5.5 | — | 0.3% | Dec 31, 2002 |
20Monitor | CVE-2000-0678No exploit | PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificatpgp · pgp | Medium5.0 | — | 1.5% | Oct 20, 2000 |
20Monitor | CVE-2000-0543No exploit | The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not pgp · certificate server | Medium5.0 | — | 1.1% | Jun 14, 2000 |
19Monitor | CVE-2008-5731Proof of concept | The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause pgp · desktop · CWE-399 | Medium4.9 | — | 0.9% | Dec 26, 2008 |
18Monitor | CVE-2001-0381No exploit | The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters tpgp · openpgp | Medium4.6 | — | 0.4% | Jun 27, 2001 |
18Monitor | CVE-2001-0435No exploit | The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while pgp · pgp | Medium4.6 | — | 0.3% | Jul 2, 2001 |
17Monitor | CVE-2010-3618No exploit | PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the "Decrypt/Verify File via Right-Click" funcpgp · desktop for windows · CWE-310 | Medium4.3 | — | 1.6% | Nov 22, 2010 |
14Monitor | CVE-2000-0802No exploit | The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain accesspgp · personal privacy | Low3.6 | — | 0.3% | Oct 20, 2000 |
8Monitor | CVE-2001-0265Proof of concept | ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored fipgp · pgp | Low2.1 | — | 0.7% | Jun 18, 2001 |
8Monitor | CVE-2005-4151No exploit | The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space inpgp · desktop | Low2.1 | — | 0.5% | Dec 10, 2005 |
8Monitor | CVE-2000-0445No exploit | The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may propgp · pgp | Low2.1 | — | 0.4% | May 24, 2000 |
8Monitor | CVE-2002-1977No exploit | Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackpgp · pgp | Low2.1 | — | 0.4% | Dec 31, 2002 |
- CVE-2001-132050Plan
Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via ex
HighCVSS 7.5WeaponizedEPSS 68%pgp · keyserverJul 16, 2001
- CVE-2001-125241Plan
Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs t
CriticalCVSS 10.0No exploitEPSS 3%pgp · keyserverSep 28, 2001
- CVE-2010-339738Monitor
Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local user
CriticalCVSS 9.3No exploitEPSS 4%pgp · desktopSep 15, 2010
- CVE-2001-145632Monitor
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitra
HighCVSS 7.5No exploitEPSS 6%mcafee · webshield smtpSep 4, 2001
- CVE-2002-085031Monitor
Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long f
HighCVSS 7.5No exploitEPSS 3%pgp · corporate desktopOct 4, 2002
- CVE-2002-068531Monitor
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0
HighCVSS 7.5No exploitEPSS 3%pgp · desktop securityJul 23, 2002
- CVE-2002-206931Monitor
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to rec
HighCVSS 7.5No exploitEPSS 2%pgp · personal privacyDec 31, 2002
- CVE-2007-060330Monitor
PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgps
HighCVSS 7.1No exploitEPSS 5%pgp · corporate desktopJan 30, 2007
- CVE-2001-101630Monitor
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly
HighCVSS 7.5No exploitEPSS 1%pgp · corporate desktopSep 4, 2001
- CVE-2009-068128Monitor
PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) caus
HighCVSS 7.2No exploitEPSS 0%pgp · desktopApr 15, 2009
- CVE-2002-078822Monitor
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext
MediumCVSS 5.5No exploitEPSS 0%pgp · corporate desktopAug 12, 2002
- CVE-2002-169622Monitor
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically de
MediumCVSS 5.5No exploitEPSS 0%pgp · personal privacyDec 31, 2002
- CVE-2000-067820Monitor
PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificat
MediumCVSS 5.0No exploitEPSS 2%pgp · pgpOct 20, 2000
- CVE-2000-054320Monitor
The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not
MediumCVSS 5.0No exploitEPSS 1%pgp · certificate serverJun 14, 2000
- CVE-2008-573119Monitor
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause
MediumCVSS 4.9Proof of conceptEPSS 1%pgp · desktopDec 26, 2008
- CVE-2001-038118Monitor
The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters t
MediumCVSS 4.6No exploitEPSS 0%pgp · openpgpJun 27, 2001
- CVE-2001-043518Monitor
The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while
MediumCVSS 4.6No exploitEPSS 0%pgp · pgpJul 2, 2001
- CVE-2010-361817Monitor
PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the "Decrypt/Verify File via Right-Click" func
MediumCVSS 4.3No exploitEPSS 2%pgp · desktop for windowsNov 22, 2010
- CVE-2000-080214Monitor
The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access
LowCVSS 3.6No exploitEPSS 0%pgp · personal privacyOct 20, 2000
- CVE-2001-02658Monitor
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored fi
LowCVSS 2.1Proof of conceptEPSS 1%pgp · pgpJun 18, 2001
- CVE-2005-41518Monitor
The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in
LowCVSS 2.1No exploitEPSS 0%pgp · desktopDec 10, 2005
- CVE-2000-04458Monitor
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may pro
LowCVSS 2.1No exploitEPSS 0%pgp · pgpMay 24, 2000
- CVE-2002-19778Monitor
Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attack
LowCVSS 2.1No exploitEPSS 0%pgp · pgpDec 31, 2002