Vulnerabilities
Vulnerable Software
Irssi:  Security Vulnerabilities
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-01-06
When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.
CVSS Score
9.8
EPSS Score
0.006
Published
2018-01-06
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.
CVSS Score
7.5
EPSS Score
0.005
Published
2018-01-06
In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.
CVSS Score
9.8
EPSS Score
0.009
Published
2018-01-06
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on.
CVSS Score
7.5
EPSS Score
0.006
Published
2017-10-22
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
CVSS Score
7.5
EPSS Score
0.006
Published
2017-10-22
In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue relative to CVE-2017-9468.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-10-22
In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.
CVSS Score
5.9
EPSS Score
0.011
Published
2017-10-22
In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-10-22
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
CVSS Score
9.8
EPSS Score
0.015
Published
2017-07-07


Contact Us

Shodan ® - All rights reserved