Screen

Vendor:

First CVE: Apr 23, 2002 · Active for 24 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Screen over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2002
24 years ago
Most Recent CVE
Apr 8, 2023
1,203 days ago

CVE Severity & Scoring

Screen9 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (22.2%)
Network2 (22.2%)
Unknown5 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (44.4%)
High0 (0.0%)
Unknown5 (55.6%)
User Interaction
None4 (44.4%)
Unknown5 (55.6%)
Required0 (0.0%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None2 (22.2%)
Unknown5 (55.6%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact v
Feb 9, 20219.834NONO
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP sign
Apr 8, 20236.532NOYES
A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Scr
Feb 24, 20209.829NONO
GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue
Jun 5, 20077.227NOYES
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Mar 20, 20177.825NONO
Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) char
Dec 15, 200310.025NONO
Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.
Apr 23, 20024.621NOYES
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
Apr 1, 20094.916NONO
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to
Oct 24, 20062.612NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
33.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Screen

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.326.00.5%01
4.0.1110.03.4%00
3.9.927.32.3%01
3.9.827.32.3%01
3.9.427.32.3%01
3.9.15110.03.4%00
3.9.13110.03.4%00
3.9.1127.32.3%01
3.9.1027.32.3%01