Vulnerabilities
Vulnerable Software
Irssi:  >> Irssi  >> 0.7.94  Security Vulnerabilities
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
CVSS Score
7.5
EPSS Score
0.006
Published
2017-10-22
In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue relative to CVE-2017-9468.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-10-22
In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.
CVSS Score
5.9
EPSS Score
0.011
Published
2017-10-22
In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-10-22
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
CVSS Score
9.8
EPSS Score
0.011
Published
2017-07-07
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
CVSS Score
9.8
EPSS Score
0.008
Published
2017-07-07
In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.
CVSS Score
7.5
EPSS Score
0.014
Published
2017-06-07
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
CVSS Score
7.5
EPSS Score
0.022
Published
2017-06-07
The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
CVSS Score
9.8
EPSS Score
0.016
Published
2017-03-27
The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message without a nick.
CVSS Score
7.5
EPSS Score
0.019
Published
2017-03-03


Contact Us

Shodan ® - All rights reserved