📦

xchat_gnome

Vendor: xchat

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 0.76% Exploit Prob.
Latest CVE CVE-2013-7449 Apr 21

Security Vulnerability Index

Page 1 / 1
6.5 CVSS

The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: 0.76%