Quassel IRC is a distributed, client-server IRC application that enables users to maintain persistent chat connectivity across multiple devices, positioning it as a niche but notable component in messaging infrastructure. The vendor's vulnerability footprint, while modest in volume, reflects the complexity of network protocol parsing and session management inherent to IRC implementations. Current exploitation activity, severity levels, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quassel Irc over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000178CRITICAL A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allo | May 8, 2018 | 9.8 | 31 | NO | NO |
CVE-2016-4414HIGH The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid | Jun 13, 2016 | 7.5 | 25 | NO | NO |
CVE-2018-1000179HIGH A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhandler.cpp line 235 that allows an | May 8, 2018 | 7.5 | 24 | NO | NO |
CVE-2021-34825HIGH Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system. | Jun 17, 2021 | 7.5 | 23 | NO | NO |
CVE-2015-3427HIGH Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks | May 14, 2015 | 7.5 | 21 | NO | NO |
CVE-2014-8483MEDIUM The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string. | Nov 6, 2014 | 5.0 | 21 | NO | NO |
CVE-2015-8547HIGH The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op * | Jan 8, 2016 | 7.5 | 20 | NO | NO |
CVE-2013-4422MEDIUM SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via | Oct 23, 2013 | 6.8 | 20 | NO | NO |
CVE-2011-3354MEDIUM The CtcpParser::packedReply method in core/ctcpparser.cpp in Quassel before 0.7.3 allows remote attackers to cause a denial of service (crash) via a crafted Client-To-Client Protoc | Oct 4, 2011 | 5.0 | 18 | NO | NO |
CVE-2010-3443MEDIUM ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) | Nov 23, 2013 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quassel Irc.
Media articles that mention a CVE ID that affects a product developed by Quassel Irc — matched by CVE ID, not by vendor name.