Quassel is a modestly deployed distributed IRC client framework centered on its core server component, which maintains persistent chat connections across a network of clients. The vendor's observed vulnerability exposure centers on improper input validation in the core server, reflecting the parsing demands of the IRC protocol and network message handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quassel over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5657HIGH CRLF injection vulnerability in Quassel Core before 0.3.0.3 allows remote attackers to spoof IRC messages as other users via a crafted CTCP message. | Dec 17, 2008 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quassel.
Media articles that mention a CVE ID that affects a product developed by Quassel — matched by CVE ID, not by vendor name.