Unrealircd is a widely deployed open-source Internet Relay Chat (IRC) server whose vulnerability footprint concentrates in a single product line and recurs through memory-safety and authentication weaknesses including classic buffer overflows, improper input validation, and authentication bypass issues. These weakness classes are characteristic of network daemon codebases and reflect the parsing demands of protocol handling; the vendor's disclosures frequently acquire public exploit tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unrealircd over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2075HIGH UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_S | Jun 15, 2010 | 7.5 | 84 | NO | YES |
CVE-2009-4893MEDIUM Buffer overflow in UnrealIRCd 3.2beta11 through 3.2.8, when allow::options::noident is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute ar | Jun 15, 2010 | 6.8 | 21 | NO | NO |
CVE-2023-50784HIGH A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker to crash the server by sending an oversized packet (if a we | Dec 16, 2023 | 7.5 | 20 | NO | NO |
CVE-2016-7144HIGH The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in | Jan 18, 2017 | 8.1 | 20 | NO | NO |
CVE-2017-13649MEDIUM UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to | Aug 23, 2017 | 5.5 | 19 | NO | NO |
CVE-2013-7384MEDIUM UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, related to SSL. NOTE: this iss | May 19, 2014 | 5.0 | 19 | NO | NO |
CVE-2013-6413MEDIUM Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors. NOTE: this identifier was S | May 19, 2014 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unrealircd.
Media articles that mention a CVE ID that affects a product developed by Unrealircd — matched by CVE ID, not by vendor name.