Search CVE reports


Toggle filters

1 – 10 of 11 results


CVE-2021-33586

Medium priority
Ignored

InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-25269

Medium priority

Some fixes available 3 of 9

An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for...

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2019-20918

Unknown priority
Not affected

An issue was discovered in InspIRCd 3 before 3.1.0. The silence module contains a use after free vulnerability. This vulnerability can be used for remote crashing of an InspIRCd server by any user able to fully connect to a server.

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected Not affected Not affected
Show less packages

CVE-2019-20917

Medium priority
Fixed

An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules,...

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2012-6696

Medium priority

Some fixes available 1 of 2

inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of an incomplete fix to CVE-2012-1836.

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected
Show less packages

CVE-2015-6674

Medium priority

Some fixes available 1 of 2

Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplete fix of CVE-2012-1836.

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected
Show less packages

CVE-2012-6697

Medium priority

Some fixes available 1 of 2

InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop).

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected
Show less packages

CVE-2016-7142

Medium priority

Some fixes available 1 of 5

The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2015-8702

Medium priority

Some fixes available 2 of 3

The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a...

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd Not affected
Show less packages

CVE-2012-1836

Medium priority

Some fixes available 3 of 5

Heap-based buffer overflow in dns.cpp in InspIRCd 2.0.5 might allow remote attackers to execute arbitrary code via a crafted DNS query that uses compression.

1 affected package

inspircd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
inspircd
Show less packages