Znc is a modestly represented IRC bouncer and proxy application that maintains persistent connections to IRC networks on behalf of users, occupying a specialized niche in chat infrastructure despite its concentrated product footprint. The vulnerability profile centers on input-handling and access-control weaknesses—improper input validation, path traversal, NULL-pointer dereferences, and code-injection conditions—that recur across the core application and its containerized distributions, reflecting the parsing demands of IRC protocol handling and the sensitivity of a service that mediates authentication and message flow. Defenders should treat Znc instances as security-sensitive components, particularly when exposed to untrusted networks or run with elevated privileges; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Znc over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29577CRITICAL The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image | Dec 8, 2020 | 9.8 | 29 | NO | NO |
CVE-2019-12816HIGH Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a crafted name. | Jun 15, 2019 | 8.8 | 29 | NO | NO |
CVE-2010-2488HIGH NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections. | Nov 12, 2019 | 7.5 | 25 | NO | NO |
CVE-2020-13775MEDIUM ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network. | Jun 2, 2020 | 6.5 | 24 | NO | NO |
CVE-2018-14055MEDIUM ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf. | Jul 15, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-14056MEDIUM ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories. | Jul 15, 2018 | 5.3 | 20 | NO | NO |
CVE-2009-2658HIGH Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request. | Aug 4, 2009 | 7.5 | 20 | NO | NO |
CVE-2012-0033MEDIUM The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a denial of service (crash) via a crafted DC | Apr 8, 2014 | 5.0 | 19 | NO | NO |
CVE-2010-2934MEDIUM Multiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to cause a denial of service (exception and daemon crash) via unknown vectors related to "unsafe substr() c | Aug 17, 2010 | 5.0 | 19 | NO | NO |
CVE-2010-2812MEDIUM Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an argument. | Aug 17, 2010 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Znc.
Media articles that mention a CVE ID that affects a product developed by Znc — matched by CVE ID, not by vendor name.