Записи weechat
7 опубликованных записей вендора weechat.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-125 Out-of-bounds Read1
- CWE-190 Integer Overflow or Wraparound1
- CWE-295 Improper Certificate Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-8955Эксплойта нет | irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflweechat · weechat · CWE-120 | Критическая9,8 | — | 3,7 % | 12 февр. 2020 г. |
40В плане | CVE-2020-9760Эксплойта нет | An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected).weechat · weechat · CWE-120 | Критическая9,8 | — | 2,2 % | 23 мар. 2020 г. |
39Наблюдать | CVE-2024-46613Эксплойта нет | WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items weechat · weechat · CWE-190 | Критическая9,8 | — | 0,5 % | 10 нояб. 2024 г. |
31Наблюдать | CVE-2017-8073Эксплойта нет | WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin.weechat · weechat · CWE-119 | Высокая7,5 | — | 3,1 % | 23 апр. 2017 г. |
31Наблюдать | CVE-2017-14727Эксплойта нет | logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.weechat · logger · CWE-119 | Высокая7,5 | — | 2,8 % | 23 сент. 2017 г. |
30Наблюдать | CVE-2021-40516Эксплойта нет | WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-boundweechat · weechat · CWE-125 | Высокая7,5 | — | 1,6 % | 5 сент. 2021 г. |
19Наблюдать | CVE-2022-28352Эксплойта нет | WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after ceweechat · weechat · CWE-295 | Средняя4,8 | — | 0,4 % | 2 апр. 2022 г. |
- CVE-2020-895540В плане
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overfl
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %weechat · weechat12 февр. 2020 г.
- CVE-2020-976040В плане
An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %weechat · weechat23 мар. 2020 г.
- CVE-2024-4661339Наблюдать
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %weechat · weechat10 нояб. 2024 г.
- CVE-2017-807331Наблюдать
WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %weechat · weechat23 апр. 2017 г.
- CVE-2017-1472731Наблюдать
logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %weechat · logger23 сент. 2017 г.
- CVE-2021-4051630Наблюдать
WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bound
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %weechat · weechat5 сент. 2021 г.
- CVE-2022-2835219Наблюдать
WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after ce
СредняяCVSS 4,8Эксплойта нетEPSS 0 %weechat · weechat2 апр. 2022 г.