Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Irssi MEDIUM 5.3
CVE-2023-29132

Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-for…

Fix: 1.4.4+
Fix from $1,600 2023-04-14
Docker Image CRITICAL 9.8
CVE-2020-29602

The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker containe…

Fix: 1.1-alpine+
Fix from $2,300 2020-12-08
Irssi HIGH 8.1
CVE-2019-13045

Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.

Fix: 1.0.8 / 1.1.3+
Fix from $1,950 2019-06-29
Irssi HIGH 7.5
CVE-2017-15227

Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting i…

Fix: after 1.0.4
Fix from $1,950 2017-10-22
Irssi HIGH 7.5
CVE-2017-15228

Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.

Fix: after 1.0.4
Fix from $1,950 2017-10-22
Irssi CRITICAL 9.8
CVE-2017-10965

An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

Fix: after 1.0.3
Fix from $2,300 2017-07-07
Irssi CRITICAL 9.8
CVE-2017-10966

An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free t…

Fix: after 1.0.3
Fix from $2,300 2017-07-07
Irssi CRITICAL 9.8
CVE-2017-7191

The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code v…

Fix: after 1.0.1
Fix from $2,300 2017-03-27
Irssi HIGH 7.5
CVE-2017-5195EPSS 5%

Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code.

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Irssi HIGH 7.5
CVE-2017-5196EPSS 5%

Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are…

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Irssi MEDIUM 6.8
CVE-2010-1155

Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Su…

Fix: after 0.8.15
Fix from $1,600 2010-04-16
Irssi MEDIUM 5.0
CVE-2009-1959EPSS 8%

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (c…

No fix yet
Fix from $1,600 2009-06-08
Irssi HIGH 9.3
CVE-2007-4396

Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmm…

Fix: after 0.8.9
Fix from $1,950 2007-08-18
Irssi MEDIUM 6.8
CVE-2007-4397

Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) a2x 0.0.1, (5) Another xmms-i…

Fix: after 0.8.10rc5
Fix from $1,600 2007-08-18
Irssi MEDIUM 6.8
CVE-2007-4398

Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to exe…

Fix: after 0.8.10rc5
Fix from $1,600 2007-08-18
Irssi MEDIUM 6.8
CVE-2007-4399

CRLF injection vulnerability in the xmms.bx 1.0 script for BitchX allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF se…

Patch available
Fix from $1,600 2007-08-18
Irssi MEDIUM 5.0
CVE-2006-0458

The DCC ACCEPT command handler in irssi before 0.8.9+0.8.10rc5-0ubuntu4.1 in Ubuntu Linux, and possibly other distributions, allows remote attackers …

Patch available
Fix from $1,600 2006-03-06
Irssi MEDIUM 5.0
CVE-2003-1020

The format_send_to_gui function in formats.c for irssi before 0.8.9 allows remote IRC users to cause a denial of service (crash).

Mitigation only
Fix from $1,600 2004-01-05
Irssi HIGH 10.0
CVE-2002-1840

irssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to acc…

Patch available
Fix from $1,950 2002-12-31
Irssi MEDIUM 5.0
CVE-2002-0983

IRC client irssi in irssi-text before 0.8.4 allows remote attackers to cause a denial of service (crash) via an IRC channel that has a long topic fol…

Patch available
Fix from $1,600 2002-09-24