Mirc is an internet relay chat (IRC) client with a relatively narrow product footprint centered on its flagship desktop application and historical media-player integrations. The vulnerabilities affecting this vendor cluster around memory-safety issues, information disclosure, and argument-injection flaws typical of applications handling network protocol parsing and user-supplied input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mirc over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4449HIGH Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message. | Oct 6, 2008 | 9.3 | 65 | NO | YES |
CVE-2003-1336HIGH Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL. | Dec 31, 2003 | 9.3 | 63 | NO | YES |
CVE-2019-6453HIGH mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .i | Feb 18, 2019 | 8.1 | 60 | NO | YES |
CVE-2008-7314HIGH mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname. | Jan 23, 2020 | 7.5 | 25 | NO | NO |
CVE-2011-5282MEDIUM mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled. | Jan 21, 2020 | 5.3 | 19 | NO | NO |
CVE-2007-4402MEDIUM Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file. | Aug 18, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-4403MEDIUM The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file. | Aug 18, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-4401MEDIUM Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbit | Aug 18, 2007 | 6.8 | 18 | NO | NO |
CVE-2003-1508MEDIUM Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash | Dec 31, 2003 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mirc.
Media articles that mention a CVE ID that affects a product developed by Mirc — matched by CVE ID, not by vendor name.