Rxvt-Unicode Project Rxvt-Unicode vulnerabilities
6 known vulnerabilities affecting rxvt-unicode_project/rxvt-unicode.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2022-4170CRITICALCVSS 9.8v9.25v9.26+1 more2022-12-09
CVE-2022-4170 [CRITICAL] CWE-74 CVE-2022-4170: The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension,
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
nvdosv
CVE-2021-33477HIGHCVSS 8.8v9.222021-05-20
CVE-2021-33477 [HIGH] CWE-755 CVE-2021-33477: rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code executi
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
nvdosv
CVE-2014-3121HIGHCVSS 7.6≥ 0, < 9.20-12014-05-14
CVE-2014-3121 [HIGH] CVE-2014-3121: rxvt-unicode before 9
rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
osv
CVE-2006-0126MEDIUMCVSS 4.6≥ 0, < 6.3-12006-01-09
CVE-2006-0126 [MEDIUM] CVE-2006-0126: rxvt-unicode before 6
rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.
osv
CVE-2005-0764HIGHCVSS 7.5≥ 0, < 5.3-12005-05-02
CVE-2005-0764 [HIGH] CVE-2005-0764: Buffer overflow in command
Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences.
osv
CVE-2004-2215MEDIUMCVSS 4.6≥ 0, < 3.8-12004-12-31
CVE-2004-2215 [MEDIUM] CVE-2004-2215: RXVT-Unicode 3
RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges.
osv