« Back to list

Invisible-island

Invisible-island Xterm: vulnerabilities and CVEs

Invisible-island Xterm has 6 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months0
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-40359Critical (9.8)0.85%—Aug 14, 2023
xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm…
CVE-2022-45063Critical (9.8)5.4%—Nov 10, 2022
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the…
CVE-2022-24130Medium (5.5)1.7%—Jan 31, 2022
xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.
CVE-2021-27135Critical (9.8)7.8%—Feb 10, 2021
xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.
CVE-2008-2383High (9.3)4.9%—Jan 2, 2009
CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape…
CVE-2006-7236High (9.3)7.5%—Jan 2, 2009
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via…

Other products by Invisible-island