← Vulnerability feed

Vulnerability record · CVE-2004-0409 · published 1 June 2004

CVE-2004-0409: Xchat vulnerability

Xchat · Xchat

Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.

7.5 CVSS 2.0 High EPSS 9.0% · top 4.9%
7.5CVSS 2.0 base score
9.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0409 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-0828Gnome gtk out-of-bounds write vulnerabilityHeap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial o…EPSS 4.3%7.5CVE-2003-1000Xchat null pointer dereference vulnerabilityxchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null der…EPSS 2.6%7.5CVE-2002-0006Xchat vulnerabilityXChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clie…EPSS 8.1%7.5CVE-2002-0382Xchat vulnerabilityXChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell metachara…EPSS 2.4%7.5CVE-2001-0792Xchat vulnerabilityFormat string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.EPSS 2.8%7.5CVE-2000-0787Xchat vulnerabilityIRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which X…EPSS 9.2%6.9CVE-2009-0315Xchat vulnerabilityUntrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python file in the …EPSS 0.37%6.8CVE-2008-2841Microsoft internet explorer code injection vulnerabilityArgument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2004-0409), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.