Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.2% | — | Ircd-ratbox | 4/2/2010 | 16/6/2026 | cache.c in ircd-ratbox before 2.2.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a HELP command. | |
| Modificada | Media (6.8) | 4.0% | — | Ircd-hybridIrcd-ratboxOftc-hybrid | 4/2/2010 | 16/6/2026 | Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command. | |
| Modificada | Media (5) | 2.3% | — | Inspircd | 24/4/2008 | 16/6/2026 | Buffer overflow in InspIRCd before 1.1.18, when using the namesx and uhnames modules, allows remote attackers to cause a denial of service (daemon crash) via a large number of channel users with crafted nicknames, idents, and long hostnames. | |
| Modificada | Media (5) | 5.2% | — | IrcuQuakenet Snircd | 25/3/2008 | 16/6/2026 | The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and unspecified other ircu derivatives allows remote attackers to cause a denial of service (daemon crash) via a malformed MODE command. | |
| Modificada | Media (5) | 1.8% | — | Ngircd | 16/1/2008 | 16/6/2026 | ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference. | |
| Modificada | Media (5) | 1.7% | — | Ngircd | 20/11/2007 | 16/6/2026 | irc-channel.c in ngIRCd before 0.10.3 allows remote attackers to cause a denial of service (crash) via a JOIN command without a channel argument. | |
| Modificada | Alta (7.8) | 2.4% | — | Universal Ircd Ircu | 18/8/2007 | 16/6/2026 | ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with certain long names that differ in the final character, which triggers a protocol violation and (2) cause a denial of service (daemon crash) via a "J 0:#channel" message on a channel without an apass;… | |
| Modificada | Alta (7.5) | 1.5% | — | Universal Ircd Ircu | 18/8/2007 | 16/6/2026 | ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel during a split. | |
| Modificada | Alta (7.8) | 1.7% | — | Universal Ircd Ircu | 18/8/2007 | 16/6/2026 | ircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by creating a large number of unused channels (zannels). | |
| Modificada | Media (5) | 1.3% | — | Universal Ircd Ircu | 18/8/2007 | 16/6/2026 | ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a netjoin by causing a bounce while a server with an older version of the channel is linking. | |
| Modificada | Media (5.1) | 1.3% | — | Universal Ircd Ircu | 18/8/2007 | 16/6/2026 | Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arranging for ops privilege to be granted before the mode arrives. | |
| Modificada | Media (6) | 1.1% | — | Universal Ircd Ircu | 18/8/2007 | 16/6/2026 | ircu 2.10.12.05 and earlier does not properly synchronize a kick action in certain cross scenarios, which allows remote authenticated operators to prevent later kick or de-op actions from non-local ops. | |
| Modificada | Media (6.4) | 1.5% | — | Universal Ircd Ircu | 18/8/2007 | 16/6/2026 | ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zannel), which allows remote attackers to (1) set or remove certain channel modes via a "netriding" attack or (2) take over a channel by joining an unlinked server with the A/Upass and then setting a new Apass. | |
| Modificada | Media (4.3) | 1.2% | — | Universal Ircd Ircu | 18/8/2007 | 16/6/2026 | ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) certain other arguments that represent groups of IP addresses, then monitoring CTCP ping replies. | |
| Modificada | Media (5) | 1.7% | — | Ircd-ratbox | 21/5/2007 | 16/6/2026 | Ratbox IRC Daemon (aka ircd-ratbox) 2.2.5 and earlier allows remote attackers to cause a denial of service (resource exhaustion) by making many requests from a single client. | |
| Modificada | Media (5) | 3.8% | — | Unrealircd | 14/3/2006 | 16/6/2026 | UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denial of service by causing a linked server to send malformed TKL Q:Line commands, as demonstrated by "TKL - q\x08Q *\x08PoC." | |
| Modificada | Media (5) | 1.7% | — | Ptnet Ircd | 31/12/2005 | 16/6/2026 | The m_join function in channel.c for PTnet ircd 1.5 and 1.6 allows remote attackers to cause a denial of service (memory exhaustion that triggers a daemon restart) via a large number of requests to join a "charmed channel" such as PTnet, #PTnoticias and #*.log, which causes ircd to open the channel even though it does… | |
| Modificada | Crítica (9.8) | 19% | — | Barton Ngircd | 2/5/2005 | 16/6/2026 | Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow. | |
| Modificada | Alta (7.5) | 9.9% | — | Ngircd | 3/2/2005 | 16/6/2026 | Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 7.3% | — | Ircd-hybridIrcd-ratbox | 6/12/2004 | 16/6/2026 | Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have a rate-limit imposed, which could allow remote attackers to cause a denial of service by repeatedly making requests, which are slowly dequeued. | |
| Modificada | Media (5) | 1.6% | — | Unrealircd | 6/8/2004 | 16/6/2026 | The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user's IP addresses. | |
| Modificada | Alta (8.3) | 2.9% | — | Sircd | 31/12/2003 | 16/6/2026 | Buffer overflow in the reverse DNS lookup of Smart IRC Daemon (SIRCD) 0.4.0 and 0.4.4 allows remote attackers to execute arbitrary code via a client with a long hostname. | |
| Modificada | Media (5) | 4.2% | — | Ircnet Ircd | 17/11/2003 | 16/6/2026 | Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service. | |
| Modificada | Alta (10) | 12% | — | Andromede AdromedeircdDaniel Moss MethaneHans Westerhof DigatechWenet Ircd-ru+1 | 7/8/2003 | 16/6/2026 | Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary… | |
| Modificada | Media (6.4) | 2.7% | — | Unrealircd | 31/12/2002 | 16/6/2026 | Format string vulnerability in the Cio_PrintF function of cio_main.c in Unreal IRCd 3.1.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers. |