inspircd records
10 published records for vendor inspircd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 90%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-20 Improper Input Validation2
- CWE-416 Use After Free2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-476 NULL Pointer Dereference1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2015-6674No exploit | Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid.inspircd · inspircd · CWE-119 | Critical9.8 | — | 2.3% | Apr 13, 2017 |
39Monitor | CVE-2012-6696No exploit | inspircd in Debian before 2.0.7 does not properly handle unsigned integers.inspircd · inspircd · CWE-20 | Critical9.8 | — | 1.6% | Sep 25, 2017 |
35Monitor | CVE-2015-8702No exploit | The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an ininspircd · inspircd · CWE-20 | High8.6 | — | 2.3% | Apr 12, 2016 |
32Monitor | CVE-2012-1836No exploit | Heap-based buffer overflow in dns.cpp in InspIRCd 2.0.5 might allow remote attackers to execute arbitrary code via a crafted DNS query that inspircd · inspircd · CWE-119 | High7.5 | — | 6.8% | Mar 21, 2012 |
27Monitor | CVE-2019-20917No exploit | An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0.inspircd · inspircd · CWE-476 | Medium6.5 | — | 2.8% | Sep 11, 2020 |
27Monitor | CVE-2020-25269No exploit | An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0.inspircd · inspircd · CWE-416 | Medium6.5 | — | 2.7% | Sep 11, 2020 |
26Monitor | CVE-2019-20918No exploit | An issue was discovered in InspIRCd 3 before 3.1.0.inspircd · inspircd · CWE-416 | Medium6.5 | — | 1.5% | Sep 11, 2020 |
23Monitor | CVE-2016-7142No exploit | The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers toinspircd · inspircd · CWE-264 | Medium5.9 | — | 1.1% | Sep 26, 2016 |
21Monitor | CVE-2008-1925No exploit | Buffer overflow in InspIRCd before 1.1.18, when using the namesx and uhnames modules, allows remote attackers to cause a denial of service (inspircd · inspircd · CWE-119 | Medium5.0 | — | 2.3% | Apr 24, 2008 |
17Monitor | CVE-2021-33586No exploit | InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "minspircd · inspircd · CWE-732 | Medium4.3 | — | 0.9% | May 27, 2021 |
- CVE-2015-667440Plan
Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid.
CriticalCVSS 9.8No exploitEPSS 2%inspircd · inspircdApr 13, 2017
- CVE-2012-669639Monitor
inspircd in Debian before 2.0.7 does not properly handle unsigned integers.
CriticalCVSS 9.8No exploitEPSS 2%inspircd · inspircdSep 25, 2017
- CVE-2015-870235Monitor
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an in
HighCVSS 8.6No exploitEPSS 2%inspircd · inspircdApr 12, 2016
- CVE-2012-183632Monitor
Heap-based buffer overflow in dns.cpp in InspIRCd 2.0.5 might allow remote attackers to execute arbitrary code via a crafted DNS query that
HighCVSS 7.5No exploitEPSS 7%inspircd · inspircdMar 21, 2012
- CVE-2019-2091727Monitor
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0.
MediumCVSS 6.5No exploitEPSS 3%inspircd · inspircdSep 11, 2020
- CVE-2020-2526927Monitor
An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0.
MediumCVSS 6.5No exploitEPSS 3%inspircd · inspircdSep 11, 2020
- CVE-2019-2091826Monitor
An issue was discovered in InspIRCd 3 before 3.1.0.
MediumCVSS 6.5No exploitEPSS 1%inspircd · inspircdSep 11, 2020
- CVE-2016-714223Monitor
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to
MediumCVSS 5.9No exploitEPSS 1%inspircd · inspircdSep 26, 2016
- CVE-2008-192521Monitor
Buffer overflow in InspIRCd before 1.1.18, when using the namesx and uhnames modules, allows remote attackers to cause a denial of service (
MediumCVSS 5.0No exploitEPSS 2%inspircd · inspircdApr 24, 2008
- CVE-2021-3358617Monitor
InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "m
MediumCVSS 4.3No exploitEPSS 1%inspircd · inspircdMay 27, 2021