Vulnerabilities (CVE)

Filtered by vendor Unrealircd Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50784 1 Unrealircd 1 Unrealircd 2023-12-26 N/A 7.5 HIGH
A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker to crash the server by sending an oversized packet (if a websocket port is open). Remote code execution might be possible on some uncommon, older platforms.
CVE-2016-7144 1 Unrealircd 1 Unrealircd 2017-01-20 6.8 MEDIUM 8.1 HIGH
The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.