Ircu
Vendor:
First CVE: Aug 18, 2007 · Active for 18 years
8
Total CVEs
More Total CVEs than 85% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ircu over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2007
18 years ago
Most Recent CVE
Aug 18, 2007
6,915 days ago
CVE Severity & Scoring
Ircu8 CVEs
63%
38%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4404HIGH ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with certain long names that differ in the final character, which t | Aug 18, 2007 | 7.8 | 20 | NO | NO |
CVE-2007-4405HIGH ircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by creating a large number of unused channels (zannels). | Aug 18, 2007 | 7.8 | 20 | NO | NO |
CVE-2007-4406HIGH ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel | Aug 18, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-4407MEDIUM ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zannel), which allows remote attackers to (1) set or remove certain channel m | Aug 18, 2007 | 6.4 | 17 | NO | NO |
CVE-2007-4410MEDIUM ircu 2.10.12.05 and earlier does not properly synchronize a kick action in certain cross scenarios, which allows remote authenticated operators to prevent later kick or de-op actio | Aug 18, 2007 | 6.0 | 17 | NO | NO |
CVE-2007-4411MEDIUM ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) ce | Aug 18, 2007 | 4.3 | 16 | NO | NO |
CVE-2007-4408MEDIUM ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a netjoin by causing a bounce while a server with an older ve | Aug 18, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-4409MEDIUM Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arranging for ops privilege to be granted before the mode arriv | Aug 18, 2007 | 5.1 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Ircu
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.10.12.05 | 1 | 5.1 | 1.3% | 0 | 0 |
| 2.10.12.04 | 4 | 6.7 | 1.5% | 0 | 0 |
| 2.10.12.03 | 4 | 6.7 | 1.5% | 0 | 0 |
| 2.10.12.02 | 3 | 6.8 | 1.5% | 0 | 0 |
| 2.10.12.01 | 3 | 6.8 | 1.8% | 0 | 0 |