Universal Ircd maintains ircu, an Internet Relay Chat daemon that has occupied a specialized niche in IRC server infrastructure. The durable signal in this vendor's disclosures centers on the NVD placeholder weakness category, reflecting the historical classification practices around legacy protocol-implementation issues; defenders tracking IRC infrastructure should monitor this vendor's advisories for flaws affecting older deployments and network backbone services. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Universal Ircd over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4404HIGH ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with certain long names that differ in the final character, which t | Aug 18, 2007 | 7.8 | 20 | NO | NO |
CVE-2007-4405HIGH ircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by creating a large number of unused channels (zannels). | Aug 18, 2007 | 7.8 | 20 | NO | NO |
CVE-2007-4406HIGH ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel | Aug 18, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-4407MEDIUM ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zannel), which allows remote attackers to (1) set or remove certain channel m | Aug 18, 2007 | 6.4 | 17 | NO | NO |
CVE-2007-4410MEDIUM ircu 2.10.12.05 and earlier does not properly synchronize a kick action in certain cross scenarios, which allows remote authenticated operators to prevent later kick or de-op actio | Aug 18, 2007 | 6.0 | 17 | NO | NO |
CVE-2007-4411MEDIUM ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) ce | Aug 18, 2007 | 4.3 | 16 | NO | NO |
CVE-2007-4408MEDIUM ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a netjoin by causing a bounce while a server with an older ve | Aug 18, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-4409MEDIUM Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arranging for ops privilege to be granted before the mode arriv | Aug 18, 2007 | 5.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Universal Ircd.
Media articles that mention a CVE ID that affects a product developed by Universal Ircd — matched by CVE ID, not by vendor name.