← Vulnerability feed

Vulnerability record · CVE-2002-0425 · published 12 August 2002

CVE-2002-0425: Khaled mardam-bey mirc vulnerability

KKhaled Mardam Bey · Mirc

mIRC DCC server protocol allows remote attackers to gain sensitive information such as alternate IRC nicknames via a "100 testing" message in a DCC connection request that cannot be ignored or canceled by the user, which may leak the alternate nickname in a response message.

5.0 CVSS 2.0 Medium EPSS 1.5% · top 26.1%
5.0CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

mIRC DCC server protocol allows remote attackers to gain sensitive information such as alternate IRC nicknames via a "100 testing" message in a DCC connection request that cannot be ignored or canceled by the user, which may leak the alternate nickname in a response message.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0425 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2002-1456Khaled mardam-bey mirc vulnerabilityBuffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.EPSS 12%7.5CVE-2002-0231Khaled mardam-bey mirc vulnerabilityBuffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.EPSS 9.6%7.5CVE-2001-0315Khaled mardam-bey mirc vulnerabilityThe locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.EPSS 1.1%7.5CVE-1999-0399Khaled mardam-bey mirc vulnerabilityThe DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file…EPSS 2.7%7.2CVE-2001-0944Khaled mardam-bey mirc vulnerabilityDDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed b…EPSS 0.35%5.0CVE-2003-1512Khaled mardam-bey mirc memory buffer overflow vulnerabilityBuffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.EPSS 2.4%4.6CVE-2006-0489Khaled mardam-bey mirc vulnerabilityBuffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original resear…EPSS 0.47%4.6CVE-2005-4681Khaled mardam-bey mirc vulnerabilityBuffer overflow in mIRC 5.91, 6.03, 6.12, and 6.16 allows local users to execute arbitrary code via a long string that is entered after reaching the …EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2002-0425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.