Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2008-7314

Disclosure Date: January 23, 2020 (last updated February 21, 2025)
mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.
Attacker Value
Unknown

CVE-2011-5282

Disclosure Date: January 21, 2020 (last updated February 21, 2025)
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
Attacker Value
Unknown

CVE-2019-6453

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).
0
Attacker Value
Unknown

CVE-2008-4449

Disclosure Date: October 06, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message.
0
Attacker Value
Unknown

CVE-2008-2396

Disclosure Date: May 21, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in an arbitrary element of the PAGES array parameter.
0
Attacker Value
Unknown

CVE-2007-4402

Disclosure Date: August 18, 2007 (last updated October 04, 2023)
Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
0
Attacker Value
Unknown

CVE-2006-0489

Disclosure Date: February 01, 2006 (last updated February 22, 2025)
Buffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original researcher claims that issue has been disputed by the vendor, and that the vendor stated "as far as I can tell, this is neither an exploit nor a vulnerability. The above report describes a local bug in mIRC." It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk
0
Attacker Value
Unknown

CVE-2005-4681

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Buffer overflow in mIRC 5.91, 6.03, 6.12, and 6.16 allows local users to execute arbitrary code via a long string that is entered after reaching the DCC Get Folder Dialog. NOTE: this issue has been disputed by the vendor, saying "as far as I can tell, this is neither an exploit nor a vulnerability. The above report describes a local bug in mIRC." It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk
0
Attacker Value
Unknown

CVE-2003-1336

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.
0
Attacker Value
Unknown

CVE-2003-1508

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filename.
0