cbcvebase.

Gnu Screen vulnerabilities

16 known vulnerabilities affecting gnu/screen.

Total CVEs
16
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3MEDIUM7LOW3

Vulnerabilities

Page 1 of 1
CVE-2021-26937P3CRITICALCVSS 9.8≤ 4.8.02021-02-09
CVE-2021-26937 [CRITICAL] CWE-88 CVE-2021-26937: encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
nvdosv
CVE-2023-24626P4MEDIUMCVSS 6.5PoC≤ 4.9.02023-04-08
CVE-2023-24626 [MEDIUM] CWE-732 CVE-2023-24626: socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
nvdosv
CVE-2025-23395P3HIGHCVSS 7.3≥ 0, < 5.0.1-r02025-05-26
CVE-2025-23395 [HIGH] CVE-2025-23395: Screen 5 Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
osv
CVE-2020-9366P3CRITICALCVSS 9.8fixed in 4.8.02020-02-24
CVE-2020-9366 [CRITICAL] CWE-787 CVE-2020-9366: A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Sp A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact.
nvdosv
CVE-2007-3048P4HIGHCVSS 7.2PoCv4.0.32007-06-05
CVE-2007-3048 [HIGH] CVE-2007-3048: GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password promp GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue
nvd
CVE-2002-1602P4MEDIUMCVSS 4.6PoCv3.9.4v3.9.8+3 more2002-04-23
CVE-2002-1602 [MEDIUM] CVE-2002-1602: Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows lo Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.
nvd
CVE-2017-5618P3HIGHCVSS 7.8≤ 4.5.02017-03-20
CVE-2017-5618 [HIGH] CWE-863 CVE-2017-5618: GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root priv GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
nvdosv
CVE-2003-0972P4CRITICALCVSS 10.0v3.9.4v3.9.8+6 more2003-12-15
CVE-2003-0972 [CRITICAL] CVE-2003-0972: Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.
nvdosv
CVE-2015-6806P4MEDIUMCVSS 5.0≥ 0, < 4.3.1-22015-09-28
CVE-2015-6806 [MEDIUM] CVE-2015-6806: The MScrollV function in ansi The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequence with a large repeat count value.
osv
CVE-2025-46802P4MEDIUMCVSS 5.3≥ 0, < 4.9.1-32025-05-26
CVE-2025-46802 [MEDIUM] CVE-2025-46802: For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.
osv
CVE-2025-46803P4MEDIUMCVSS 5.1≥ 0, < 5.0.1-r02025-05-26
CVE-2025-46803 [MEDIUM] CVE-2025-46803: The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.
osv
CVE-2025-46805P4MEDIUMCVSS 5.7≥ 0, < 4.9.1-32025-05-26
CVE-2025-46805 [MEDIUM] CVE-2025-46805: Screen version 5 Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.
osv
CVE-2009-1214P4MEDIUMCVSS 4.9v4.0.32009-04-01
CVE-2009-1214 [MEDIUM] CWE-264 CVE-2009-1214: GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, wh GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
nvdosv
CVE-2025-46804P4LOWCVSS 2.0≥ 0, < 4.9.1_git20250512-r0≥ 0, < 5.0.1-r02025-05-26
CVE-2025-46804 [LOW] CVE-2025-46804: A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would other A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.
osv
CVE-2006-4573P4LOWCVSS 2.6≤ 4.0.22006-10-24
CVE-2006-4573 [LOW] CVE-2006-4573: Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb f Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.
nvdosv
CVE-2009-1215P4LOWCVSS 1.9≥ 0, < 4.0.3-132009-04-01
CVE-2009-1215 [LOW] CVE-2009-1215: Race condition in GNU screen 4 Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
osv
Gnu Screen vulnerabilities | cvebase