Bitchx is a legacy IRC client with a niche but persistent user base, where its vulnerability profile reflects challenges common to interactive network applications and file-handling utilities. The durable signal centers on input validation, information-disclosure, and memory-safety issues spanning sensitive data exposure, improper link resolution, and buffer boundary violations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bitchx over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4584HIGH Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable. | Aug 29, 2007 | 10.0 | 44 | NO | YES |
CVE-2007-3360HIGH hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a | Jun 22, 2007 | 9.3 | 40 | NO | YES |
CVE-2003-1450MEDIUM BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message. | Dec 31, 2003 | 5.0 | 23 | NO | YES |
CVE-2007-5922MEDIUM The modules/mdop.m in the Cypress 1.0k script for BitchX, as downloaded from a distribution site in November 2007, contains an externally introduced backdoor that e-mails sensitive | Nov 10, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-5839MEDIUM The e_hostname function in commands.c in BitchX 1.1a allows local users to overwrite arbitrary files via a symlink attack on temporary files when using the (1) HOSTNAME or (2) IRCH | Nov 6, 2007 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bitchx.
Media articles that mention a CVE ID that affects a product developed by Bitchx — matched by CVE ID, not by vendor name.