cbcvebase.
CVE-2014-3121
published 2014-05-14

CVE-2014-3121: rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties…

PriorityP346high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
4.10%
89.6th percentile
rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianrxvt-unicode< rxvt-unicode 9.20-1 (bookworm)rxvt-unicode 9.20-1 (bookworm)
marc_lehmannrxvt-unicode<= 9.19
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
marc_lehmannrxvt-unicode
rxvt-unicode_projectrxvt-unicode>= 0 < 9.20-19.20-1
rxvt-unicode_projectrxvt-unicode>= 0 < 9.20-19.20-1
rxvt-unicode_projectrxvt-unicode>= 0 < 9.20-19.20-1
rxvt-unicode_projectrxvt-unicode>= 0 < 9.20-19.20-1

CVSS provenance

nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
vendor_debian7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.