Vulnerabilities > Inspircd > Inspircd > 2.0.9

DATE CVE VULNERABILITY TITLE RISK
2020-09-11 CVE-2020-25269 Use After Free vulnerability in multiple products
An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0.
network
low complexity
inspircd debian CWE-416
6.5
2020-09-11 CVE-2019-20917 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0.
network
low complexity
inspircd debian CWE-476
6.5
2017-04-13 CVE-2015-6674 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid.
network
low complexity
inspircd debian CWE-119
7.5
2016-09-26 CVE-2016-7142 Permissions, Privileges, and Access Controls vulnerability in multiple products
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
4.3
2016-04-12 CVE-2015-8702 Improper Input Validation vulnerability in multiple products
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.
network
low complexity
debian inspircd CWE-20
7.8