Screen
Vendor:
First CVE: Apr 23, 2002 · Active for 24 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Screen over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2002
24 years ago
Most Recent CVE
Apr 8, 2023
1,203 days ago
CVE Severity & Scoring
Screen9 CVEs
11%
33%
33%
22%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (22.2%)
Network2 (22.2%)
Unknown5 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (44.4%)
High0 (0.0%)
Unknown5 (55.6%)
User Interaction
None4 (44.4%)
Unknown5 (55.6%)
Required0 (0.0%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None2 (22.2%)
Unknown5 (55.6%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26937CRITICAL encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact v | Feb 9, 2021 | 9.8 | 34 | NO | NO |
CVE-2023-24626MEDIUM socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP sign | Apr 8, 2023 | 6.5 | 32 | NO | YES |
CVE-2020-9366CRITICAL A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Scr | Feb 24, 2020 | 9.8 | 29 | NO | NO |
CVE-2007-3048HIGH GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue | Jun 5, 2007 | 7.2 | 27 | NO | YES |
CVE-2017-5618HIGH GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions. | Mar 20, 2017 | 7.8 | 25 | NO | NO |
CVE-2003-0972HIGH Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) char | Dec 15, 2003 | 10.0 | 25 | NO | NO |
CVE-2002-1602MEDIUM Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code. | Apr 23, 2002 | 4.6 | 21 | NO | YES |
CVE-2009-1214MEDIUM GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information. | Apr 1, 2009 | 4.9 | 16 | NO | NO |
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to | Oct 24, 2006 | 2.6 | 12 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
33.3% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Screen
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.3 | 2 | 6.0 | 0.5% | 0 | 1 |
| 4.0.1 | 1 | 10.0 | 3.4% | 0 | 0 |
| 3.9.9 | 2 | 7.3 | 2.3% | 0 | 1 |
| 3.9.8 | 2 | 7.3 | 2.3% | 0 | 1 |
| 3.9.4 | 2 | 7.3 | 2.3% | 0 | 1 |
| 3.9.15 | 1 | 10.0 | 3.4% | 0 | 0 |
| 3.9.13 | 1 | 10.0 | 3.4% | 0 | 0 |
| 3.9.11 | 2 | 7.3 | 2.3% | 0 | 1 |
| 3.9.10 | 2 | 7.3 | 2.3% | 0 | 1 |