Unrealircd

Unrealircd

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.98%
  • Veröffentlicht 16.12.2023 23:15:40
  • Zuletzt bearbeitet 04.11.2025 19:16:14

A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker to crash the server by sending an oversized packet (if a websocket port is open). Remote code execution might be possible on some...

  • EPSS 0.05%
  • Veröffentlicht 23.08.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script e...

  • EPSS 2.39%
  • Veröffentlicht 18.01.2017 17:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

  • EPSS 0.73%
  • Veröffentlicht 19.05.2014 14:55:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, related to SSL. NOTE: this issue was SPLIT from CVE-2013-6413 per ADT2 due to different vulnerabilit...

  • EPSS 0.73%
  • Veröffentlicht 19.05.2014 14:55:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7384 was ...

  • EPSS 1.67%
  • Veröffentlicht 15.06.2010 14:04:26
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in UnrealIRCd 3.2beta11 through 3.2.8, when allow::options::noident is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

Exploit
  • EPSS 86.38%
  • Veröffentlicht 15.06.2010 14:04:26
  • Zuletzt bearbeitet 11.04.2025 00:51:21

UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary comman...