Lucene search

K
cve[email protected]CVE-2014-3121
HistoryMay 14, 2014 - 12:55 a.m.

CVE-2014-3121

2014-05-1400:55:10
CWE-78
web.nvd.nist.gov
33
rxvt-unicode
vulnerability
osc escape sequences
cve-2014-3121
nvd

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%

rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.

Affected configurations

NVD
Node
marc_lehmannrxvt-unicodeRange9.19
OR
marc_lehmannrxvt-unicodeMatch9.0
OR
marc_lehmannrxvt-unicodeMatch9.01
OR
marc_lehmannrxvt-unicodeMatch9.02
OR
marc_lehmannrxvt-unicodeMatch9.05
OR
marc_lehmannrxvt-unicodeMatch9.06
OR
marc_lehmannrxvt-unicodeMatch9.07
OR
marc_lehmannrxvt-unicodeMatch9.08
OR
marc_lehmannrxvt-unicodeMatch9.09
OR
marc_lehmannrxvt-unicodeMatch9.10
OR
marc_lehmannrxvt-unicodeMatch9.11
OR
marc_lehmannrxvt-unicodeMatch9.12
OR
marc_lehmannrxvt-unicodeMatch9.14
OR
marc_lehmannrxvt-unicodeMatch9.15
OR
marc_lehmannrxvt-unicodeMatch9.16
OR
marc_lehmannrxvt-unicodeMatch9.17
OR
marc_lehmannrxvt-unicodeMatch9.18

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%