Rxvt Unicode Project maintains rxvt-unicode, a terminal emulator that, despite a narrow product scope, serves a niche but dedicated user base in Unix-like environments. The vendor's disclosed vulnerabilities have been associated with terminal-parsing and input-handling weaknesses characteristic of text-rendering applications. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rxvt Unicode Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4170CRITICAL The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certai | Dec 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-33477HIGH rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A respons | May 20, 2021 | 8.8 | 28 | NO | NO |
CVE-2006-0126MEDIUM rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devi | Jan 9, 2006 | 4.6 | 14 | NO | NO |
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that | Apr 7, 2008 | 3.7 | 13 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rxvt Unicode Project.
Media articles that mention a CVE ID that affects a product developed by Rxvt Unicode Project — matched by CVE ID, not by vendor name.