Vulnerabilities
32 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-29132 | Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2020-29602 | The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2019-15717 | Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP. Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2019-13045 | Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server. Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server. NVD description · AI analysis pending | 8.1 | 3% |
| — | ||
| CVE-2019-5882 | Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer. Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2018-7053 | An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2018-5208 | In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings. In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2017-15721 | In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue relative to CVE-2017-9468. NVD description · AI analysis pending | 7.5 group max | 2% |
| — | ||
| CVE-2017-10965 +1 in the same advisory: …10966 | An issue was discovered in Irssi before 1.0.4. An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2017-9469 +1 in the same advisory: …9468 | In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash. NVD description · AI analysis pending | 7.5 | 6% |
| — | ||
| CVE-2017-7191 | The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecif The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2017-5193 | The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message without a ni The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message without a nick. NVD description · AI analysis pending | 7.5 | 6% |
| — | ||
| CVE-2016-7553 | The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local user The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file. NVD description · AI analysis pending | 3.3 | <1% |
| — | ||
| CVE-2016-7045 +1 in the same advisory: …7044 | The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and cras The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string. NVD description · AI analysis pending | 7.5 | 5% | PoC |
| — |