Vulnerabilities > Atheme

DATE CVE VULNERABILITY TITLE RISK
2022-02-14 CVE-2022-24976 Improper Authentication vulnerability in Atheme
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
network
atheme CWE-287
5.8
2017-03-02 CVE-2017-6384 Missing Release of Resource after Effective Lifetime vulnerability in Atheme 7.2.7
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service.
network
low complexity
atheme CWE-772
7.8
2016-06-13 CVE-2016-4478 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
network
low complexity
opensuse atheme debian CWE-119
5.0
2016-06-13 CVE-2014-9773 Improper Access Control vulnerability in multiple products
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
network
low complexity
opensuse atheme CWE-284
5.0
2012-10-01 CVE-2012-1576 Permissions, Privileges, and Access Controls vulnerability in Atheme
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.
network
atheme CWE-264
6.0