Konversation is an IRC client with a narrow but more-than-negligible presence in the vulnerability record, where disclosures cluster around its chat application. The recurring weakness classes—improper input validation and protocol-parsing issues—reflect the attack surface inherent to a client handling untrusted network messages. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Konversation over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-5050HIGH konversation before 1.2.3 allows attackers to cause a denial of service. | Nov 6, 2019 | 7.5 | 25 | NO | NO |
CVE-2017-15923HIGH Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes. | Nov 15, 2017 | 7.5 | 25 | NO | NO |
CVE-2007-4400MEDIUM CRLF injection vulnerability in the included media script in Konversation allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of | Aug 18, 2007 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Konversation.
Media articles that mention a CVE ID that affects a product developed by Konversation — matched by CVE ID, not by vendor name.