CVE-2024-39844
- EPSS 26.73%
- Veröffentlicht 03.07.2024 17:15:04
- Zuletzt bearbeitet 21.11.2024 09:28:25
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
CVE-2020-13775
- EPSS 0.97%
- Veröffentlicht 02.06.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:50
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.
CVE-2010-2488
- EPSS 1.31%
- Veröffentlicht 12.11.2019 20:15:09
- Zuletzt bearbeitet 21.11.2024 01:16:45
NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.
CVE-2019-12816
- EPSS 2.71%
- Veröffentlicht 15.06.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:23:38
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a crafted name.
CVE-2019-9917
- EPSS 1.66%
- Veröffentlicht 27.03.2019 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:34
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
CVE-2018-14055
- EPSS 0.38%
- Veröffentlicht 15.07.2018 01:29:03
- Zuletzt bearbeitet 21.11.2024 03:48:31
ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf.
CVE-2018-14056
- EPSS 0.69%
- Veröffentlicht 15.07.2018 01:29:03
- Zuletzt bearbeitet 21.11.2024 03:48:32
ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.
- EPSS 1.27%
- Veröffentlicht 19.12.2014 15:59:32
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by adding a channel with the same name as an existing channel but withou...
- EPSS 1.09%
- Veröffentlicht 05.06.2014 20:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) editnetwork, (2) editchan, (3) addchan, or (4) delchan page in modules/webadmin.cpp.
- EPSS 2.35%
- Veröffentlicht 17.08.2010 22:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an argument.