Vulnerabilities > Irssi > Irssi > 1.0.4

DATE CVE VULNERABILITY TITLE RISK
2017-10-22 CVE-2017-15723 NULL Pointer Dereference vulnerability in multiple products
In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.
network
low complexity
irssi debian CWE-476
5.0
2017-10-22 CVE-2017-15722 Out-of-bounds Read vulnerability in multiple products
In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.
network
irssi debian CWE-125
4.3
2017-10-22 CVE-2017-15721 NULL Pointer Dereference vulnerability in multiple products
In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference.
network
low complexity
irssi debian CWE-476
5.0
2017-10-22 CVE-2017-15228 Out-of-bounds Read vulnerability in Irssi
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
network
low complexity
irssi CWE-125
5.0
2017-10-22 CVE-2017-15227 Use After Free vulnerability in Irssi
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on.
network
low complexity
irssi CWE-416
5.0