CVE Browser

CVE-2024-39844 CRITICAL

In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

CVSS 9.8 EPSS 3.86% Jul 3, 2024
CVE-2020-29577 CRITICAL

The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions…

CVSS 9.8 EPSS 2.32% Dec 8, 2020
CVE-2020-13775 MEDIUM

ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there…

CVSS 6.5 EPSS 1.85% Jun 2, 2020
CVE-2010-2488 HIGH

NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.

CVSS 7.5 EPSS 2.40% Nov 12, 2019
CVE-2019-12816 HIGH

Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a cr…

CVSS 8.8 EPSS 4.05% Jun 15, 2019
CVE-2019-9917 MEDIUM

ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.

CVSS 6.5 EPSS 3.08% Mar 27, 2019
CVE-2018-14056 MEDIUM

ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.

CVSS 5.3 EPSS 2.02% Jul 15, 2018
CVE-2018-14055 MEDIUM

ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue v…

CVSS 6.5 EPSS 1.46% Jul 15, 2018
CVE-2014-9403 MEDIUM

The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of service (NULL pointer dere…

CVSS 4.0 EPSS 2.16% Dec 19, 2014
CVE-2013-2130 MEDIUM

ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) editnetwork, (2) edi…

CVSS 4.0 EPSS 2.21% Jun 5, 2014
CVE-2012-0033 MEDIUM

The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a denial of service (cr…

CVSS 5.0 EPSS 2.49% Apr 8, 2014
CVE-2013-7049 MEDIUM

Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earlier, allows remote attackers to cause a…

CVSS 4.3 EPSS 1.66% Dec 23, 2013
CVE-2010-2934 MEDIUM

Multiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to cause a denial of service (exception and daemon crash) via unknown vectors related…

CVSS 5.0 EPSS 3.08% Aug 17, 2010
CVE-2010-2812 MEDIUM

Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an argument.

CVSS 5.0 EPSS 3.16% Aug 17, 2010
CVE-2010-2448 LOW

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active una…

CVSS 3.5 EPSS 2.06% Jul 12, 2010
CVE-2009-2658 HIGH

Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.

CVSS 7.5 EPSS 2.92% Aug 4, 2009
CVE-2009-0759 MEDIUM

Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file and gain pri…

CVSS 6.5 EPSS 2.10% Mar 3, 2009

Showing 1 to 17 CVEs · page 1