Vulnerabilities > Irssi

DATE CVE VULNERABILITY TITLE RISK
2018-01-06 CVE-2018-5208 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.
network
low complexity
irssi debian CWE-119
critical
9.8
2018-01-06 CVE-2018-5207 Use of Externally-Controlled Format String vulnerability in multiple products
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.
network
low complexity
irssi debian CWE-134
7.5
2018-01-06 CVE-2018-5206 NULL Pointer Dereference vulnerability in multiple products
When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.
network
low complexity
irssi debian CWE-476
critical
9.8
2018-01-06 CVE-2018-5205 Use of Externally-Controlled Format String vulnerability in multiple products
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
network
low complexity
irssi debian canonical CWE-134
7.5
2017-10-22 CVE-2017-15723 NULL Pointer Dereference vulnerability in multiple products
In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.
network
low complexity
irssi debian CWE-476
7.5
2017-10-22 CVE-2017-15722 Out-of-bounds Read vulnerability in multiple products
In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.
network
high complexity
irssi debian CWE-125
5.9
2017-10-22 CVE-2017-15721 NULL Pointer Dereference vulnerability in multiple products
In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference.
network
low complexity
irssi debian CWE-476
7.5
2017-10-22 CVE-2017-15228 Out-of-bounds Read vulnerability in Irssi
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
network
low complexity
irssi CWE-125
7.5
2017-10-22 CVE-2017-15227 Use After Free vulnerability in Irssi
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on.
network
low complexity
irssi CWE-416
7.5
2017-07-07 CVE-2017-10966 Use After Free vulnerability in Irssi
An issue was discovered in Irssi before 1.0.4.
network
low complexity
irssi CWE-416
critical
9.8