Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PBitlbee
APPBitlbee0.710.720.730.740.800.810.820.830.840.850.900.910.920.930.99+ 9 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2012-1187CRITICAL9.8PL ✓same product
BitlBee — nieprawidłowe porzucanie uprawnień grupowych (privilege escalation)
CVE-2016-10188CRITICAL9.8PL ✓same product
Use-after-free w bitlbee-libpurple umożliwiający RCE lub DoS
CVE-2017-5668CRITICAL9.8PL ✓same product
NULL pointer dereference w bitlbee-libpurple umożliwiający RCE/DoS
CVE-2016-10189HIGH7.5same product
BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) a...
CVE-2008-3969MEDIUM5.0same product
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack...