Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.58% | — | UnrealircdAI | 13/9/2026 | 22/9/2026 | The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled… | |
| Modificada | Alta (7.5) | 1.9% | — | Unrealircd | 16/12/2023 | 17/6/2026 | A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker to crash the server by sending an oversized packet (if a websocket port is open). Remote code execution might be possible on some uncommon, older platforms. | |
| Modificada | Media (4.3) | 0.89% | — | Inspircd | 27/5/2021 | 17/6/2026 | InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue. | |
| Modificada | Media (6.5) | 2.7% | — | InspircdDebian Linux | 11/9/2020 | 17/6/2026 | An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server. | |
| Modificada | Media (6.5) | 1.5% | — | Inspircd | 11/9/2020 | 17/6/2026 | An issue was discovered in InspIRCd 3 before 3.1.0. The silence module contains a use after free vulnerability. This vulnerability can be used for remote crashing of an InspIRCd server by any user able to fully connect to a server. | |
| Modificada | Media (6.5) | 2.8% | — | InspircdDebian Linux | 11/9/2020 | 17/6/2026 | An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user… | |
| Modificada | Alta (7.5) | 2.6% | — | Barton NgircdDebian LinuxFedoraproject Fedora | 15/6/2020 | 17/6/2026 | The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. | |
| Modificada | Alta (7.5) | 1.9% | — | Ircd-ratbox | 26/12/2019 | 17/6/2026 | A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler. | |
| Modificada | Crítica (9.8) | 1.6% | — | Inspircd | 25/9/2017 | 16/6/2026 | inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of an incomplete fix to CVE-2012-1836. | |
| Modificada | Media (5.5) | 0.28% | — | Unrealircd | 23/8/2017 | 17/6/2026 | UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command. NOTE: the vendor indicates… | |
| Modificada | Crítica (9.8) | 2.3% | — | InspircdDebian Linux | 13/4/2017 | 17/6/2026 | Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplete fix of CVE-2012-1836. | |
| Modificada | Alta (7.5) | 1.9% | — | Inspire Ircd InspircdDebian Linux | 13/4/2017 | 16/6/2026 | InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop). | |
| Modificada | Alta (8.1) | 1.3% | — | Unrealircd | 18/1/2017 | 17/6/2026 | The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter. | |
| Modificada | Media (5.9) | 1.1% | — | InspircdDebian Linux | 26/9/2016 | 17/6/2026 | The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message. | |
| Modificada | Alta (8.6) | 2.3% | — | Debian LinuxInspircd | 12/4/2016 | 17/6/2026 | The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname. | |
| Modificada | Media (5) | 2.4% | — | Unrealircd | 19/5/2014 | 17/6/2026 | UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, related to SSL. NOTE: this issue was SPLIT from CVE-2013-6413 per ADT2 due to different vulnerability types. | |
| Modificada | Media (5) | 2.4% | — | Unrealircd | 19/5/2014 | 17/6/2026 | Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7384 was assigned for the NULL pointer dereference. | |
| Modificada | Media (4.3) | 2.3% | — | Barton Ngircd | 1/10/2013 | 16/6/2026 | The (1) Conn_StartLogin and (2) cb_Read_Resolver_Result functions in conn.c in ngIRCd 18 through 20.2, when the configuration option NoticeAuth is enabled, does not properly handle the return code for the Handle_Write function, which allows remote attackers to cause a denial of service (assertion failure and server… | |
| Modificada | Media (5) | 2.7% | — | Ngircd | 28/3/2013 | 16/6/2026 | channel.c in ngIRCd 20 and 20.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a KICK command for a user who is not on the associated channel. | |
| Modificada | Media (5) | 10.0% | — | Ircd-hybrid | 13/2/2013 | 16/6/2026 | The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a denial of service (crash) via a mask that causes a negative number to be parsed. | |
| Modificada | Media (5) | 3.0% | — | Ircd-ratboxIrcd-ratbox | 1/1/2013 | 16/6/2026 | modules/m_capab.c in (1) ircd-ratbox before 3.0.8 and (2) Charybdis before 3.4.2 does not properly support capability negotiation during server handshakes, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request. | |
| Modificada | Alta (7.5) | 6.8% | — | Inspircd | 22/3/2012 | 16/6/2026 | Heap-based buffer overflow in dns.cpp in InspIRCd 2.0.5 might allow remote attackers to execute arbitrary code via a crafted DNS query that uses compression. | |
| Modificada | Alta (7.5) | 84% | — | Unrealircd | 15/6/2010 | 16/6/2026 | UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (6.8) | 2.5% | — | Unrealircd | 15/6/2010 | 16/6/2026 | Buffer overflow in UnrealIRCd 3.2beta11 through 3.2.8, when allow::options::noident is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Baja (2.6) | 1.6% | — | Ngircd | 26/2/2010 | 16/6/2026 | The (1) Conn_GetCipherInfo and (2) Conn_UsesSSL functions in src/ngircd/conn.c in ngIRCd 13 and 14, when SSL/TLS support is present and standalone mode is disabled, allow remote attackers to cause a denial of service (application crash) by sending the MOTD command from another server in the same IRC network, possibly… |