Skip to main content

Vendor archive

irssi CVEs

Beta · best-effort

43 CVEs tagged to vendor irssi12 Critical, 19 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2023-29132

Published Apr 14, 2023

Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29602

Published Dec 8, 2020

The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker container deployed by affected version…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-13045

Published Jun 29, 2019

Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15721

Published Oct 22, 2017

In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue relative to CVE-2017-9468.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15228

Published Oct 22, 2017

Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15227

Published Oct 22, 2017

Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions wh…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10966

Published Jul 7, 2017

An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. Thi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-10965

Published Jul 7, 2017

An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9469

Published Jun 7, 2017

In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers mig…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9468

Published Jun 7, 2017

In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7191

Published Mar 27, 2017

The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5356

Published Mar 3, 2017

Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 43 CVEsPage 1 of 2