atheme records
6 published records for vendor atheme.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-772 Missing Release of Resource after Effective Lifetime1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2022-24976No exploit | Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certatheme · atheme · CWE-287 | Critical9.1 | — | 1.8% | Feb 14, 2022 |
31Monitor | CVE-2016-4478No exploit | Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers toatheme · atheme · CWE-119 | High7.5 | — | 2.3% | Jun 13, 2016 |
31Monitor | CVE-2014-9773No exploit | modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (atheme · atheme · CWE-284 | High7.5 | — | 2.0% | Jun 13, 2016 |
31Monitor | CVE-2017-6384No exploit | Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to coatheme · atheme · CWE-772 | High7.5 | — | 2.0% | Mar 2, 2017 |
30Monitor | CVE-2024-27508No exploit | Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.atheme · atheme · CWE-401 | High7.5 | — | 0.7% | Feb 27, 2024 |
25Monitor | CVE-2012-1576No exploit | The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not proatheme · atheme · CWE-264 | Medium6.0 | — | 2.0% | Oct 1, 2012 |
- CVE-2022-2497637Monitor
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a cert
CriticalCVSS 9.1No exploitEPSS 2%atheme · athemeFeb 14, 2022
- CVE-2016-447831Monitor
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to
HighCVSS 7.5No exploitEPSS 2%atheme · athemeJun 13, 2016
- CVE-2014-977331Monitor
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (
HighCVSS 7.5No exploitEPSS 2%atheme · athemeJun 13, 2016
- CVE-2017-638431Monitor
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to co
HighCVSS 7.5No exploitEPSS 2%atheme · athemeMar 2, 2017
- CVE-2024-2750830Monitor
Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.
HighCVSS 7.5No exploitEPSS 1%atheme · athemeFeb 27, 2024
- CVE-2012-157625Monitor
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not pro
MediumCVSS 6.0No exploitEPSS 2%atheme · athemeOct 1, 2012