Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2023-50784

Disclosure Date: December 16, 2023 (last updated December 22, 2023)
A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker to crash the server by sending an oversized packet (if a websocket port is open). Remote code execution might be possible on some uncommon, older platforms.
Attacker Value
Unknown

CVE-2017-13649

Disclosure Date: August 23, 2017 (last updated November 26, 2024)
UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command. NOTE: the vendor indicates that there is no common or recommended scenario in which a root script would execute this kill command.
0
Attacker Value
Unknown

CVE-2016-7144

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
0
Attacker Value
Unknown

CVE-2013-6413

Disclosure Date: May 19, 2014 (last updated October 05, 2023)
Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7384 was assigned for the NULL pointer dereference.
0
Attacker Value
Unknown

CVE-2013-7384

Disclosure Date: May 19, 2014 (last updated October 05, 2023)
UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, related to SSL. NOTE: this issue was SPLIT from CVE-2013-6413 per ADT2 due to different vulnerability types.
0
Attacker Value
Unknown

CVE-2010-2075

Disclosure Date: June 15, 2010 (last updated October 04, 2023)
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.
0
Attacker Value
Unknown

CVE-2009-4893

Disclosure Date: June 15, 2010 (last updated October 04, 2023)
Buffer overflow in UnrealIRCd 3.2beta11 through 3.2.8, when allow::options::noident is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-1214

Disclosure Date: March 14, 2006 (last updated February 22, 2025)
UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denial of service by causing a linked server to send malformed TKL Q:Line commands, as demonstrated by "TKL - q\x08Q *\x08PoC."
0
Attacker Value
Unknown

CVE-2004-0679

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user's IP addresses.
0
Attacker Value
Unknown

CVE-2002-1675

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Format string vulnerability in the Cio_PrintF function of cio_main.c in Unreal IRCd 3.1.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers.
0