ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23558
In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp.

In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.

NVD description · AI analysis pending
6.3<1% PoC
  • eternal terminal project eternal terminal
CVE-2022-48258
+1 in the same advisory: …48257
In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.

In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.

NVD description · AI analysis pending
5.31% PoC
  • eternal terminal project eternal terminal
CVE-2022-24950
+3 in the same advisory: …24949 …24951 …24952
A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabli

A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().

NVD description · AI analysis pending
7.5
group max
1% PoC
  • eternal terminal project eternal terminal
CVE-2021-29376
ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and client crash, disconnecting the victim from an IRC server) vi

ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and client crash, disconnecting the victim from an IRC server) via a crafted CTCP UTC message.

NVD description · AI analysis pending
7.52%
  • eterna ircii
  • eterna debian linux