Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2019-15915

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.
Attacker Value
Unknown

CVE-2018-14055

Disclosure Date: July 15, 2018 (last updated November 27, 2024)
ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf.
0
Attacker Value
Unknown

CVE-2018-14056

Disclosure Date: July 15, 2018 (last updated November 27, 2024)
ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.
0
Attacker Value
Unknown

CVE-2014-9403

Disclosure Date: December 19, 2014 (last updated October 05, 2023)
The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by adding a channel with the same name as an existing channel but without the leading # character, related to a "use-after-delete" error.
0
Attacker Value
Unknown

CVE-2013-2130

Disclosure Date: June 05, 2014 (last updated October 05, 2023)
ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) editnetwork, (2) editchan, (3) addchan, or (4) delchan page in modules/webadmin.cpp.
0
Attacker Value
Unknown

CVE-2012-0033

Disclosure Date: April 08, 2014 (last updated October 05, 2023)
The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a denial of service (crash) via a crafted DCC RESUME request.
0
Attacker Value
Unknown

CVE-2013-7049

Disclosure Date: December 23, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earlier, allows remote attackers to cause a denial of service (crash) via a long string in a DH1080_INIT message.
0
Attacker Value
Unknown

CVE-2010-2812

Disclosure Date: August 17, 2010 (last updated October 04, 2023)
Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an argument.
0
Attacker Value
Unknown

CVE-2010-2934

Disclosure Date: August 17, 2010 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to cause a denial of service (exception and daemon crash) via unknown vectors related to "unsafe substr() calls."
0
Attacker Value
Unknown

CVE-2010-2448

Disclosure Date: July 12, 2010 (last updated October 04, 2023)
znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.
0