ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-4170
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's

The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

NVD description · AI analysis pending
9.82%
  • rxvt-unicode project rxvt-unicode
  • rxvt-unicode project extra packages for enterprise linux
  • rxvt-unicode project fedora
CVE-2021-33477
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences

rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.

NVD description · AI analysis pending
8.84% PoC ×2
  • eterm project eterm
  • eterm project mrxvt
  • eterm project rxvt-unicode
  • +1 more
CVE-2016-10578
unicode loads unicode data downloaded from unicode.org into nodejs.

unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.

NVD description · AI analysis pending
8.1<1%
  • unicode project unicode