Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Quassel Irc

First CVE: Oct 4, 2011Active for: 15 yearsTotal CVEs: 26

Quassel IRC is a distributed, client-server IRC application that enables users to maintain persistent chat connectivity across multiple devices, positioning it as a niche but notable component in messaging infrastructure. The vendor's vulnerability footprint, while modest in volume, reflects the complexity of network protocol parsing and session management inherent to IRC implementations. Current exploitation activity, severity levels, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Quassel Irc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2011
14 years ago
Most Recent CVE
Jun 17, 2021
1,863 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1000178CRITICAL
A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allo
May 8, 20189.831NONO
CVE-2016-4414HIGH
The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid
Jun 13, 20167.525NONO
CVE-2018-1000179HIGH
A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhandler.cpp line 235 that allows an
May 8, 20187.524NONO
CVE-2021-34825HIGH
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
Jun 17, 20217.523NONO
CVE-2015-3427HIGH
Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks
May 14, 20157.521NONO
CVE-2014-8483MEDIUM
The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
Nov 6, 20145.021NONO
CVE-2015-8547HIGH
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *
Jan 8, 20167.520NONO
CVE-2013-4422MEDIUM
SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via
Oct 23, 20136.820NONO
CVE-2011-3354MEDIUM
The CtcpParser::packedReply method in core/ctcpparser.cpp in Quassel before 0.7.3 allows remote attackers to cause a denial of service (crash) via a crafted Client-To-Client Protoc
Oct 4, 20115.018NONO
CVE-2010-3443MEDIUM
ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP)
Nov 23, 20135.017NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
54%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (38.5%)
Unknown8 (61.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (38.5%)
High0 (0.0%)
Unknown8 (61.5%)
User Interaction
None5 (38.5%)
Unknown8 (61.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (38.5%)
Unknown8 (61.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Quassel Irc.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Quassel Irc — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Quassel Irc's Products

View all 2 CNAs →

Top CWEs