← Vulnerability feed

Vulnerability record · CVE-2019-20918 · published 11 September 2020

CVE-2019-20918: Inspircd use after free vulnerability

Inspircd · Inspircd

An issue was discovered in InspIRCd 3 before 3.1.0. The silence module contains a use after free vulnerability. This vulnerability can be used for remote crashing of an InspIRCd server by any user able to fully connect to a server.

6.5 CVSS 3.1 Medium EPSS 1.5% · top 27.0% CWE-416 · Use after free
6.5CVSS 3.1 base score, v2 6.8
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in InspIRCd 3 before 3.1.0. The silence module contains a use after free vulnerability. This vulnerability can be used for remote crashing of an InspIRCd server by any user able to fully connect to a server.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-20918 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-6696Inspircd improper input validation vulnerabilityinspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of an incomplete fix to CVE-2012-…EPSS 1.6%9.8CVE-2015-6674Inspircd memory buffer overflow vulnerabilityBuffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This iss…EPSS 2.3%8.6CVE-2015-8702Debian linux improper input validation vulnerabilityThe DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid cha…EPSS 2.3%7.5CVE-2012-1836Inspircd memory buffer overflow vulnerabilityHeap-based buffer overflow in dns.cpp in InspIRCd 2.0.5 might allow remote attackers to execute arbitrary code via a crafted DNS query that uses comp…EPSS 6.8%6.5CVE-2019-20917Inspircd null pointer dereference vulnerabilityAn issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against maria…EPSS 2.8%6.5CVE-2020-25269Inspircd use after free vulnerabilityAn issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with …EPSS 2.7%5.9CVE-2016-7142Inspircd permissions and access controls vulnerabilityThe m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof ce…EPSS 1.1%5.0CVE-2008-1925Inspircd memory buffer overflow vulnerabilityBuffer overflow in InspIRCd before 1.1.18, when using the namesx and uhnames modules, allows remote attackers to cause a denial of service (daemon cr…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2019-20918), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.