Search CVE reports


Toggle filters

11 – 15 of 15 results


CVE-2012-5534

Medium priority
Ignored

The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."

1 affected package

weechat

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
weechat
Show less packages

CVE-2012-5854

Medium priority
Ignored

Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.

1 affected package

weechat

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
weechat
Show less packages

CVE-2011-1428

Medium priority
Ignored

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof...

1 affected package

weechat

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
weechat
Show less packages

CVE-2009-0661

Low priority

Some fixes available 2 of 4

Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.

1 affected package

weechat

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
weechat
Show less packages

CVE-2007-4398

Medium priority

Some fixes available 2 of 4

Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.

1 affected package

weechat-scripts

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
weechat-scripts
Show less packages