Eggheads develops Eggdrop, a widely deployed IRC bot framework used for channel automation and moderation across internet relay chat networks, with vulnerabilities clustering around its core bot implementation and containerized distributions. The observed exposure centers on input-handling and protocol-parsing concerns typical of long-running daemon and network-communication software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eggheads over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2807MEDIUM Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long priv | May 22, 2007 | 6.8 | 37 | NO | YES |
CVE-2020-29576CRITICAL The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker | Dec 8, 2020 | 9.8 | 29 | NO | NO |
CVE-2009-1789MEDIUM mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty | May 26, 2009 | 4.3 | 27 | NO | YES |
CVE-2004-0274HIGH Share.mod in Eggheads Eggdrop IRC bot 1.6.10 through 1.6.15 can mistakenly assign STAT_OFFERED status to a bot that is not a sharebot, which allows remote attackers to use STAT_OFF | Nov 23, 2004 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eggheads.
Media articles that mention a CVE ID that affects a product developed by Eggheads — matched by CVE ID, not by vendor name.