xchat records
12 published records for vendor xchat.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-310 Cryptographic Issues1
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2012-0828No exploit | Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause axchat · xchat · CWE-787 | Critical9.8 | — | 4.3% | Feb 21, 2020 |
33Monitor | CVE-2000-0787Proof of concept | IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URxchat · xchat | High7.5 | — | 9.2% | Oct 20, 2000 |
33Monitor | CVE-2004-0409Proof of concept | Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to exxchat · xchat | High7.5 | — | 9.0% | Jun 1, 2004 |
32Monitor | CVE-2008-2841Proof of concept | Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute xchat · xchat · CWE-94 | Medium6.8 | — | 15.4% | Jun 24, 2008 |
32Monitor | CVE-2002-0006Proof of concept | XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as oxchat · xchat | High7.5 | — | 8.1% | Jun 25, 2002 |
31Monitor | CVE-2001-0792No exploit | Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.xchat · xchat | High7.5 | — | 2.8% | Oct 18, 2001 |
31Monitor | CVE-2003-1000No exploit | xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes axchat · xchat · CWE-476 | High7.5 | — | 2.6% | Jan 5, 2004 |
31Monitor | CVE-2002-0382No exploit | XChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell xchat · xchat | High7.5 | — | 2.4% | Jun 25, 2002 |
27Monitor | CVE-2009-0315No exploit | Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python filxchat · xchat | Medium6.9 | — | 0.4% | Jan 28, 2009 |
26Monitor | CVE-2013-7449No exploit | The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matxchat · xchat · CWE-310 | Medium6.5 | — | 0.8% | Apr 21, 2016 |
22Monitor | CVE-2011-5129Proof of concept | Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbixchat · xchat · CWE-119 | Medium5.0 | — | 7.7% | Aug 30, 2012 |
22Monitor | CVE-2006-4455Proof of concept | Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors inxchat · xchat | Medium5.0 | — | 5.1% | Aug 30, 2006 |
- CVE-2012-082840Plan
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a
CriticalCVSS 9.8No exploitEPSS 4%xchat · xchatFeb 21, 2020
- CVE-2000-078733Monitor
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a UR
HighCVSS 7.5Proof of conceptEPSS 9%xchat · xchatOct 20, 2000
- CVE-2004-040933Monitor
Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to ex
HighCVSS 7.5Proof of conceptEPSS 9%xchat · xchatJun 1, 2004
- CVE-2008-284132Monitor
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute
MediumCVSS 6.8Proof of conceptEPSS 15%xchat · xchatJun 24, 2008
- CVE-2002-000632Monitor
XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as o
HighCVSS 7.5Proof of conceptEPSS 8%xchat · xchatJun 25, 2002
- CVE-2001-079231Monitor
Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.
HighCVSS 7.5No exploitEPSS 3%xchat · xchatOct 18, 2001
- CVE-2003-100031Monitor
xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a
HighCVSS 7.5No exploitEPSS 3%xchat · xchatJan 5, 2004
- CVE-2002-038231Monitor
XChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell
HighCVSS 7.5No exploitEPSS 2%xchat · xchatJun 25, 2002
- CVE-2009-031527Monitor
Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python fil
MediumCVSS 6.9No exploitEPSS 0%xchat · xchatJan 28, 2009
- CVE-2013-744926Monitor
The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname mat
MediumCVSS 6.5No exploitEPSS 1%xchat · xchatApr 21, 2016
- CVE-2011-512922Monitor
Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbi
MediumCVSS 5.0Proof of conceptEPSS 8%xchat · xchatAug 30, 2012
- CVE-2006-445522Monitor
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors in
MediumCVSS 5.0Proof of conceptEPSS 5%xchat · xchatAug 30, 2006