← Vulnerability feed

Vulnerability record · CVE-2002-0006 · published 25 June 2002

CVE-2002-0006: Xchat vulnerability

Xchat · Xchat

XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the client response when the percascii variable is set.

7.5 CVSS 2.0 High EPSS 8.1% · top 5.4%
7.5CVSS 2.0 base score
8.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the client response when the percascii variable is set.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-0828Gnome gtk out-of-bounds write vulnerabilityHeap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial o…EPSS 4.3%7.5CVE-2004-0409Xchat vulnerabilityStack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arb…EPSS 9.0%7.5CVE-2003-1000Xchat null pointer dereference vulnerabilityxchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null der…EPSS 2.6%7.5CVE-2002-0382Xchat vulnerabilityXChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell metachara…EPSS 2.4%7.5CVE-2001-0792Xchat vulnerabilityFormat string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.EPSS 2.8%7.5CVE-2000-0787Xchat vulnerabilityIRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which X…EPSS 9.2%6.9CVE-2009-0315Xchat vulnerabilityUntrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python file in the …EPSS 0.37%6.8CVE-2008-2841Microsoft internet explorer code injection vulnerabilityArgument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2002-0006), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.