Записи xchat
12 опубликованных записей вендора xchat.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 25 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-310 Cryptographic Issues1
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2012-0828Эксплойта нет | Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause axchat · xchat · CWE-787 | Критическая9,8 | — | 4,3 % | 21 февр. 2020 г. |
33Наблюдать | CVE-2000-0787Proof of concept | IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URxchat · xchat | Высокая7,5 | — | 9,2 % | 20 окт. 2000 г. |
33Наблюдать | CVE-2004-0409Proof of concept | Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to exxchat · xchat | Высокая7,5 | — | 9,0 % | 1 июн. 2004 г. |
32Наблюдать | CVE-2008-2841Proof of concept | Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute xchat · xchat · CWE-94 | Средняя6,8 | — | 15,4 % | 24 июн. 2008 г. |
32Наблюдать | CVE-2002-0006Proof of concept | XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as oxchat · xchat | Высокая7,5 | — | 8,1 % | 25 июн. 2002 г. |
31Наблюдать | CVE-2001-0792Эксплойта нет | Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.xchat · xchat | Высокая7,5 | — | 2,8 % | 18 окт. 2001 г. |
31Наблюдать | CVE-2003-1000Эксплойта нет | xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes axchat · xchat · CWE-476 | Высокая7,5 | — | 2,6 % | 5 янв. 2004 г. |
31Наблюдать | CVE-2002-0382Эксплойта нет | XChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell xchat · xchat | Высокая7,5 | — | 2,4 % | 25 июн. 2002 г. |
27Наблюдать | CVE-2009-0315Эксплойта нет | Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python filxchat · xchat | Средняя6,9 | — | 0,4 % | 28 янв. 2009 г. |
26Наблюдать | CVE-2013-7449Эксплойта нет | The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matxchat · xchat · CWE-310 | Средняя6,5 | — | 0,8 % | 21 апр. 2016 г. |
22Наблюдать | CVE-2011-5129Proof of concept | Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbixchat · xchat · CWE-119 | Средняя5,0 | — | 7,7 % | 30 авг. 2012 г. |
22Наблюдать | CVE-2006-4455Proof of concept | Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors inxchat · xchat | Средняя5,0 | — | 5,1 % | 30 авг. 2006 г. |
- CVE-2012-082840В плане
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %xchat · xchat21 февр. 2020 г.
- CVE-2000-078733Наблюдать
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a UR
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %xchat · xchat20 окт. 2000 г.
- CVE-2004-040933Наблюдать
Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to ex
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %xchat · xchat1 июн. 2004 г.
- CVE-2008-284132Наблюдать
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute
СредняяCVSS 6,8Proof of conceptEPSS 15 %xchat · xchat24 июн. 2008 г.
- CVE-2002-000632Наблюдать
XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as o
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %xchat · xchat25 июн. 2002 г.
- CVE-2001-079231Наблюдать
Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %xchat · xchat18 окт. 2001 г.
- CVE-2003-100031Наблюдать
xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %xchat · xchat5 янв. 2004 г.
- CVE-2002-038231Наблюдать
XChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %xchat · xchat25 июн. 2002 г.
- CVE-2009-031527Наблюдать
Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python fil
СредняяCVSS 6,9Эксплойта нетEPSS 0 %xchat · xchat28 янв. 2009 г.
- CVE-2013-744926Наблюдать
The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname mat
СредняяCVSS 6,5Эксплойта нетEPSS 1 %xchat · xchat21 апр. 2016 г.
- CVE-2011-512922Наблюдать
Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbi
СредняяCVSS 5,0Proof of conceptEPSS 8 %xchat · xchat30 авг. 2012 г.
- CVE-2006-445522Наблюдать
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors in
СредняяCVSS 5,0Proof of conceptEPSS 5 %xchat · xchat30 авг. 2006 г.