CVE-2014-3121

rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
marc_lehmannrxvt-unicode
𝑥
≤ 9.19
marc_lehmannrxvt-unicode
9.0
marc_lehmannrxvt-unicode
9.01
marc_lehmannrxvt-unicode
9.02
marc_lehmannrxvt-unicode
9.05
marc_lehmannrxvt-unicode
9.06
marc_lehmannrxvt-unicode
9.07
marc_lehmannrxvt-unicode
9.08
marc_lehmannrxvt-unicode
9.09
marc_lehmannrxvt-unicode
9.10
marc_lehmannrxvt-unicode
9.11
marc_lehmannrxvt-unicode
9.12
marc_lehmannrxvt-unicode
9.14
marc_lehmannrxvt-unicode
9.15
marc_lehmannrxvt-unicode
9.16
marc_lehmannrxvt-unicode
9.17
marc_lehmannrxvt-unicode
9.18
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rxvt-unicode
bullseye
9.22-11
fixed
bookworm
9.30-2
fixed
sid
9.31-3
fixed
trixie
9.31-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rxvt-unicode
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
quantal
ignored
precise
ignored
lucid
ignored