Weechat

Weechat

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 10.11.2024 21:15:14
  • Zuletzt bearbeitet 19.11.2024 21:35:06

WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_fr...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 02.04.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:57:11

WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle attackers to spoof a TLS chat server via an a...

  • EPSS 0.98%
  • Veröffentlicht 05.09.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:24:17

WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.

  • EPSS 1.05%
  • Veröffentlicht 23.03.2020 16:15:17
  • Zuletzt bearbeitet 21.11.2024 05:41:14

An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buffer overflow and possibly a crash can happen when a new mode is set for a nick.

  • EPSS 14.21%
  • Veröffentlicht 12.02.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 05:39:44

irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel m...

  • EPSS 1.64%
  • Veröffentlicht 23.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occurs in the irc_ctcp_dcc_filename_without_quotes function during quote removal, with a buffer overflow.