mIRC records
9 published records for vendor mirc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 22.2%
- Pre-auth RCE
- 6
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2008-4449Weaponized | Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message.mirc · mirc · CWE-119 | Critical9.3 | — | 38.7% | Oct 6, 2008 |
48Plan | CVE-2019-6453Proof of concept | mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.mirc · mirc · CWE-88 | High8.1 | — | 54.3% | Feb 18, 2019 |
48Plan | CVE-2003-1336Weaponized | Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.mirc · mirc · CWE-119 | Critical9.3 | — | 35.7% | Dec 31, 2003 |
30Monitor | CVE-2008-7314No exploit | mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.mirc · mirc · CWE-400 | High7.5 | — | 1.3% | Jan 23, 2020 |
28Monitor | CVE-2007-4402No exploit | Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter imirc · mirc | Medium6.8 | — | 3.2% | Aug 18, 2007 |
28Monitor | CVE-2007-4403No exploit | The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter imirc · plug-in for winamp · CWE-264 | Medium6.8 | — | 2.9% | Aug 18, 2007 |
28Monitor | CVE-2007-4401No exploit | Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-asmirc · advanced integration plugin | Medium6.8 | — | 2.4% | Aug 18, 2007 |
21Monitor | CVE-2011-5282No exploit | mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.mirc · mirc · CWE-200 | Medium5.3 | — | 1.1% | Jan 21, 2020 |
18Monitor | CVE-2003-1508No exploit | Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attacmirc · mirc · CWE-119 | Medium4.3 | — | 2.1% | Dec 31, 2003 |
- CVE-2008-444949Plan
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message.
CriticalCVSS 9.3WeaponizedEPSS 39%mirc · mircOct 6, 2008
- CVE-2019-645348Plan
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.
HighCVSS 8.1Proof of conceptEPSS 54%mirc · mircFeb 18, 2019
- CVE-2003-133648Plan
Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.
CriticalCVSS 9.3WeaponizedEPSS 36%mirc · mircDec 31, 2003
- CVE-2008-731430Monitor
mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.
HighCVSS 7.5No exploitEPSS 1%mirc · mircJan 23, 2020
- CVE-2007-440228Monitor
Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter i
MediumCVSS 6.8No exploitEPSS 3%mirc · mircAug 18, 2007
- CVE-2007-440328Monitor
The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter i
MediumCVSS 6.8No exploitEPSS 3%mirc · plug-in for winampAug 18, 2007
- CVE-2007-440128Monitor
Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-as
MediumCVSS 6.8No exploitEPSS 2%mirc · advanced integration pluginAug 18, 2007
- CVE-2011-528221Monitor
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
MediumCVSS 5.3No exploitEPSS 1%mirc · mircJan 21, 2020
- CVE-2003-150818Monitor
Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attac
MediumCVSS 4.3No exploitEPSS 2%mirc · mircDec 31, 2003