weechat records
7 published records for vendor weechat.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-125 Out-of-bounds Read1
- CWE-190 Integer Overflow or Wraparound1
- CWE-295 Improper Certificate Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-8955No exploit | irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflweechat · weechat · CWE-120 | Critical9.8 | — | 3.7% | Feb 12, 2020 |
40Plan | CVE-2020-9760No exploit | An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected).weechat · weechat · CWE-120 | Critical9.8 | — | 2.2% | Mar 23, 2020 |
39Monitor | CVE-2024-46613No exploit | WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items weechat · weechat · CWE-190 | Critical9.8 | — | 0.5% | Nov 10, 2024 |
31Monitor | CVE-2017-8073No exploit | WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin.weechat · weechat · CWE-119 | High7.5 | — | 3.1% | Apr 23, 2017 |
31Monitor | CVE-2017-14727No exploit | logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.weechat · logger · CWE-119 | High7.5 | — | 2.8% | Sep 23, 2017 |
30Monitor | CVE-2021-40516No exploit | WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-boundweechat · weechat · CWE-125 | High7.5 | — | 1.6% | Sep 5, 2021 |
19Monitor | CVE-2022-28352No exploit | WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after ceweechat · weechat · CWE-295 | Medium4.8 | — | 0.4% | Apr 2, 2022 |
- CVE-2020-895540Plan
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overfl
CriticalCVSS 9.8No exploitEPSS 4%weechat · weechatFeb 12, 2020
- CVE-2020-976040Plan
An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected).
CriticalCVSS 9.8No exploitEPSS 2%weechat · weechatMar 23, 2020
- CVE-2024-4661339Monitor
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items
CriticalCVSS 9.8No exploitEPSS 0%weechat · weechatNov 10, 2024
- CVE-2017-807331Monitor
WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin.
HighCVSS 7.5No exploitEPSS 3%weechat · weechatApr 23, 2017
- CVE-2017-1472731Monitor
logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.
HighCVSS 7.5No exploitEPSS 3%weechat · loggerSep 23, 2017
- CVE-2021-4051630Monitor
WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bound
HighCVSS 7.5No exploitEPSS 2%weechat · weechatSep 5, 2021
- CVE-2022-2835219Monitor
WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after ce
MediumCVSS 4.8No exploitEPSS 0%weechat · weechatApr 2, 2022