← Back

Atheme

atheme

Vendor: Atheme • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atheme
1Atheme
May 23, 2025
Feb 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.
1Atheme
1Atheme
Nov 21, 2024
Feb 14, 2022
N/A· v4
9.1 CRITICAL· v3
5.8 MEDIUM· v2
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
1Atheme
1Atheme
May 13, 2026
Mar 2, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in 7.2.8.
3Atheme
DebianOpensuse
4Atheme
Debian LinuxLeap+1 more
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
2Atheme
Opensuse
3Atheme
LeapOpensuse
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
1Atheme
1Atheme
Apr 29, 2026
Oct 1, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attack...Show more
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.Show less