Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rxvt Unicode Project

First CVE: Jan 9, 2006Active for: 21 yearsTotal CVEs: 6

Rxvt Unicode Project maintains rxvt-unicode, a terminal emulator that, despite a narrow product scope, serves a niche but dedicated user base in Unix-like environments. The vendor's disclosed vulnerabilities have been associated with terminal-parsing and input-handling weaknesses characteristic of text-rendering applications. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 56% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 89% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rxvt Unicode Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2006
20 years ago
Most Recent CVE
Dec 9, 2022
1,323 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-4170CRITICAL
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certai
Dec 9, 20229.831NONO
CVE-2021-33477HIGH
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A respons
May 20, 20218.828NONO
CVE-2006-0126MEDIUM
rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devi
Jan 9, 20064.614NONO
CVE-2008-1142LOW
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that
Apr 7, 20083.713NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
25%
25%
25%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (50.0%)
Unknown2 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (50.0%)
High0 (0.0%)
Unknown2 (50.0%)
User Interaction
None2 (50.0%)
Unknown2 (50.0%)
Required0 (0.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None1 (25.0%)
Unknown2 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rxvt Unicode Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rxvt Unicode Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rxvt Unicode Project's Products

View all 2 CNAs →

Top CWEs