← Vulnerability feed

Vulnerability record · CVE-2001-1016 · published 4 September 2001

CVE-2001-1016: Pgp corporate desktop vulnerability

PPgp · Corporate Desktop

PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."

7.5 CVSS 2.0 High EPSS 1.4% · top 29.4%
7.5CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-1016 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2002-0850Pgp corporate desktop vulnerabilityBuffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long filename w…EPSS 3.2%7.5CVE-2002-0685Pgp desktop security vulnerabilityHeap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Perso…EPSS 2.6%7.1CVE-2007-0603Pgp corporate desktop vulnerabilityPGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv na…EPSS 5.2%5.5CVE-2002-0788Pgp corporate desktop vulnerabilityAn interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporar…EPSS 0.38%5.0CVE-2000-0678Pgp vulnerabilityPGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which …EPSS 1.5%4.6CVE-2001-0435Pgp vulnerabilityThe split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on…EPSS 0.33%2.1CVE-2002-1977Pgp vulnerabilityNetwork Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to op…EPSS 0.35%2.1CVE-2001-0265Pgp vulnerabilityASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.EPSS 0.72%

Source: NIST National Vulnerability Database (record CVE-2001-1016), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.