InspIRCd is a modular, open-source Internet Relay Chat daemon whose vulnerability profile, while concentrated in a single product, reaches a prominent position within the IRC infrastructure landscape. Vulnerabilities affecting InspIRCd skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including memory-buffer issues, input-validation flaws, use-after-free conditions, permission assignment errors, and NULL-pointer dereferences that are characteristic of native C++ network services. Defenders running IRC infrastructure should treat InspIRCd advisories as high-priority for patching; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inspircd over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6696CRITICAL inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of an incomplete fix to CVE-2012-1836. | Sep 25, 2017 | 9.8 | 31 | NO | NO |
CVE-2012-1836HIGH Heap-based buffer overflow in dns.cpp in InspIRCd 2.0.5 might allow remote attackers to execute arbitrary code via a crafted DNS query that uses compression. | Mar 22, 2012 | 7.5 | 27 | NO | NO |
CVE-2015-6674CRITICAL Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issu | Apr 13, 2017 | 9.8 | 24 | NO | NO |
CVE-2020-25269MEDIUM An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, | Sep 11, 2020 | 6.5 | 23 | NO | NO |
CVE-2019-20917MEDIUM An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. | Sep 11, 2020 | 6.5 | 23 | NO | NO |
CVE-2019-20918MEDIUM An issue was discovered in InspIRCd 3 before 3.1.0. The silence module contains a use after free vulnerability. This vulnerability can be used for remote crashing of an InspIRCd se | Sep 11, 2020 | 6.5 | 22 | NO | NO |
CVE-2015-8702HIGH The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as de | Apr 12, 2016 | 8.6 | 22 | NO | NO |
CVE-2021-33586MEDIUM InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue. | May 27, 2021 | 4.3 | 18 | NO | NO |
CVE-2008-1925MEDIUM Buffer overflow in InspIRCd before 1.1.18, when using the namesx and uhnames modules, allows remote attackers to cause a denial of service (daemon crash) via a large number of chan | Apr 24, 2008 | 5.0 | 18 | NO | NO |
CVE-2016-7142MEDIUM The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and cons | Sep 26, 2016 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inspircd.
Media articles that mention a CVE ID that affects a product developed by Inspircd — matched by CVE ID, not by vendor name.