Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gnu screen vulnerabilities and exploits
(subscribe to this query)
890
VMScore
CVE-2003-0972
Integer signedness error in ansi.c for GNU screen 4.0.1 and previous versions, and 3.9.15 and previous versions, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.
Gnu Screen 3.9.15
Gnu Screen 3.9.4
Gnu Screen 3.9.11
Gnu Screen 3.9.13
Gnu Screen 3.9.8
Gnu Screen 3.9.9
Gnu Screen 3.9.10
Gnu Screen 4.0.1
725
VMScore
CVE-2007-3048
GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue
Gnu Screen 4.0.3
1 EDB exploit
668
VMScore
CVE-2021-26937
encoding.c in GNU Screen up to and including 4.8.0 allows remote malicious users to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
Gnu Screen
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
668
VMScore
CVE-2020-9366
A buffer overflow was found in the way GNU Screen prior to 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact.
Gnu Screen
643
VMScore
CVE-2017-5618
GNU screen prior to 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Gnu Screen
465
VMScore
CVE-2002-1602
Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.
Gnu Screen 3.9.11
Gnu Screen 3.9.4
Gnu Screen 3.9.10
Gnu Screen 3.9.8
Gnu Screen 3.9.9
1 EDB exploit
445
VMScore
CVE-2015-6806
The MScrollV function in ansi.c in GNU screen 4.3.1 and previous versions does not properly limit recursion, which allows remote malicious users to cause a denial of service (stack consumption) via an escape sequence with a large repeat count value.
Gnu Gnu Screen
436
VMScore
CVE-2009-1214
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
Gnu Screen 4.0.3
231
VMScore
CVE-2006-4573
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen prior to 4.0.3 allows user-assisted malicious users to cause a denial of service (crash or hang) via certain UTF8 sequences.
Gnu Screen
170
VMScore
CVE-2009-1215
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
Gnu Gnu Screen 4.0.3
2 Github repositories
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »