Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Stuart Nevans Locke

#15624of 53,632
17.3Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2021-22913
7.5
2021-09-05
Weechat · Weechat · CVE-2021-40516
**Name of the Vulnerable Software and Affected Versions** WeeChat versions prior to 3.2.1 **Description** The issue allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that triggers an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin. **Recommendations** For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue. As a temporary workaround, consider disabling the Relay plugin until a patch is available. Restrict access to the `relay-websocket.c` module to minimize the risk of exploitation.
PT-2020-20393
9.8
2020-02-12
Weechat · Weechat · CVE-2020-8955
**Name of the Vulnerable Software and Affected Versions** WeeChat versions through 2.7 **Description** The issue allows remote attackers to cause a denial of service, resulting in a buffer overflow and application crash, or possibly have other unspecified impacts via a malformed IRC message 324, which is related to channel mode. **Recommendations** For WeeChat versions through 2.7, update to a version later than 2.7 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.