Vulnerabilities
Vulnerable Software
Irssi:  Security Vulnerabilities
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
CVSS Score
9.8
EPSS Score
0.008
Published
2017-07-07
In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.
CVSS Score
7.5
EPSS Score
0.014
Published
2017-06-07
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
CVSS Score
7.5
EPSS Score
0.022
Published
2017-06-07
The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
CVSS Score
9.8
EPSS Score
0.016
Published
2017-03-27
The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message without a nick.
CVSS Score
7.5
EPSS Score
0.019
Published
2017-03-03
Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an invalid nick message.
CVSS Score
7.5
EPSS Score
0.019
Published
2017-03-03
Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-03-03
Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are not UTF8.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-03-03
Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).
CVSS Score
7.5
EPSS Score
0.028
Published
2017-03-03
The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.
CVSS Score
3.3
EPSS Score
0.001
Published
2017-02-27


Contact Us

Shodan ® - All rights reserved