Quassel Irc
quassel-irc
13 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (13)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Quassel Irc2Fedora QuasselNov 21, 2024 Jun 17, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system. |
2Debian Quassel Irc2Debian Linux QuasselNov 21, 2024 May 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhandler.cpp line 235 that allows an attacker to cause a denial of service. |
2Debian Quassel Irc2Debian Linux QuasselNov 21, 2024 May 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allows an attacker to execute code remotely. |
3Fedoraproject OpensuseQuassel Irc4Fedora LeapOpensuse+1 moreMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data. |
2Opensuse Quassel Irc3Leap OpensuseQuasselMay 6, 2026 Jan 8, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query. |
2Debian Quassel Irc2Debian Linux QuasselMay 6, 2026 May 14, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks via a \ (backslash) in a message. NOTE...Show more |
Stack consumption vulnerability in the message splitting functionality in Quassel before 0.12-rc1 allows remote attackers to cause a denial of service (uncontrolled recursion) via a crafted massage. |
Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to cause a denial of service (crash) via a long CTCP query containing only multibyte characters. |
4Canonical DebianOpensuse+1 more4Debian Linux OpensuseQuassel Irc+1 moreMay 6, 2026 Nov 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string. |
Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16...Show more |
2Canonical Quassel Irc2Quassel Irc Ubuntu LinuxApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIVMSG message. |
SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message. |
The CtcpParser::packedReply method in core/ctcpparser.cpp in Quassel before 0.7.3 allows remote attackers to cause a denial of service (crash) via a crafted Client-To-Client Protocol (CTCP) request, as demonstrated in th...Show more |