Vulnerabilities > Dconnect

DATE CVE VULNERABILITY TITLE RISK
2006-08-14 CVE-2006-4127 Format String vulnerability in Dconnect Daemon 0.0.2/0.0.3/0.7.0
Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and earlier allow remote administrators to execute arbitrary code via format string specifiers that are not properly handled when calling the (1) privmsg() or (2) pubmsg functions from (a) cmd.user.c, (b) penalties.c, or (c) cmd.dc.c.
network
high complexity
dconnect
4.6
2006-08-14 CVE-2006-4126 Denial of Service vulnerability in Dconnect Daemon 0.0.2/0.0.3/0.7.0
The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by sending a client message before providing the nickname, which triggers a null pointer dereference.
network
low complexity
dconnect
5.0
2006-08-14 CVE-2006-4125 Remote Buffer Overflow vulnerability in Dconnect Daemon 0.0.2/0.0.3/0.7.0
Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, which is not properly handled by the listen_thread_udp function.
network
low complexity
dconnect
7.5