3.7

CVE-2008-1142

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections.  NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected.  NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

Data is provided by the National Vulnerability Database (NVD)
AtermAterm Version <= 1.0.0
AtermAterm Version0.1.0
AtermAterm Version0.1.1
AtermAterm Version0.2.0
AtermAterm Version0.3.0
AtermAterm Version0.3.1
AtermAterm Version0.3.2
AtermAterm Version0.3.3
AtermAterm Version0.3.4
AtermAterm Version0.3.5
AtermAterm Version0.3.6
AtermAterm Version0.4.0
AtermAterm Version0.4.1
AtermAterm Version0.4.2
AtermAterm Version1.00 Updatebeta1
AtermAterm Version1.00 Updatebeta2
AtermAterm Version1.00 Updatebeta3
AtermAterm Version1.00 Updatebeta4
EtermEterm Version <= 0.9.3
EtermEterm Version0.9.2
MrxvtMrxvt Version <= 0.5.2
MrxvtMrxvt Version0.4.2
Multi-atermMulti-aterm Version <= 0.2
Multi-atermMulti-aterm Version0.0.1
Multi-atermMulti-aterm Version0.0.3
Multi-atermMulti-aterm Version0.0.4
Multi-atermMulti-aterm Version0.0.5
Multi-atermMulti-aterm Version0.1
RxvtRxvt Version <= 2.7.9
RxvtRxvt Version2.6.1
RxvtRxvt Version2.6.2
RxvtRxvt Version2.6.3
RxvtRxvt Version2.6.4
RxvtRxvt Version2.7.5
RxvtRxvt Version2.7.6
RxvtRxvt Version2.7.7
RxvtRxvt Version2.7.8
Rxvt-unicodeRxvt-unicode Version <= 9.01
Rxvt-unicodeRxvt-unicode Version1.0
Rxvt-unicodeRxvt-unicode Version1.1
Rxvt-unicodeRxvt-unicode Version1.2
Rxvt-unicodeRxvt-unicode Version1.3
Rxvt-unicodeRxvt-unicode Version1.4
Rxvt-unicodeRxvt-unicode Version1.5
Rxvt-unicodeRxvt-unicode Version1.6
Rxvt-unicodeRxvt-unicode Version1.7
Rxvt-unicodeRxvt-unicode Version1.8
Rxvt-unicodeRxvt-unicode Version1.9
Rxvt-unicodeRxvt-unicode Version1.91
Rxvt-unicodeRxvt-unicode Version2.0
Rxvt-unicodeRxvt-unicode Version2.1
Rxvt-unicodeRxvt-unicode Version2.2
Rxvt-unicodeRxvt-unicode Version2.3
Rxvt-unicodeRxvt-unicode Version2.4
Rxvt-unicodeRxvt-unicode Version2.5
Rxvt-unicodeRxvt-unicode Version2.6
Rxvt-unicodeRxvt-unicode Version2.7
Rxvt-unicodeRxvt-unicode Version2.8
Rxvt-unicodeRxvt-unicode Version2.9
Rxvt-unicodeRxvt-unicode Version3.0
Rxvt-unicodeRxvt-unicode Version3.1
Rxvt-unicodeRxvt-unicode Version3.2
Rxvt-unicodeRxvt-unicode Version3.3
Rxvt-unicodeRxvt-unicode Version3.4
Rxvt-unicodeRxvt-unicode Version3.5
Rxvt-unicodeRxvt-unicode Version3.6
Rxvt-unicodeRxvt-unicode Version3.7
Rxvt-unicodeRxvt-unicode Version3.8
Rxvt-unicodeRxvt-unicode Version3.9
Rxvt-unicodeRxvt-unicode Version4.0
Rxvt-unicodeRxvt-unicode Version4.1
Rxvt-unicodeRxvt-unicode Version4.2
Rxvt-unicodeRxvt-unicode Version4.3
Rxvt-unicodeRxvt-unicode Version4.4
Rxvt-unicodeRxvt-unicode Version4.5
Rxvt-unicodeRxvt-unicode Version4.6
Rxvt-unicodeRxvt-unicode Version4.7
Rxvt-unicodeRxvt-unicode Version4.8
Rxvt-unicodeRxvt-unicode Version4.9
Rxvt-unicodeRxvt-unicode Version5.0
Rxvt-unicodeRxvt-unicode Version5.1
Rxvt-unicodeRxvt-unicode Version5.2
Rxvt-unicodeRxvt-unicode Version5.3
Rxvt-unicodeRxvt-unicode Version5.4
Rxvt-unicodeRxvt-unicode Version5.5
Rxvt-unicodeRxvt-unicode Version5.6
Rxvt-unicodeRxvt-unicode Version5.7
Rxvt-unicodeRxvt-unicode Version5.8
Rxvt-unicodeRxvt-unicode Version5.9
Rxvt-unicodeRxvt-unicode Version6.0
Rxvt-unicodeRxvt-unicode Version6.1
Rxvt-unicodeRxvt-unicode Version6.2
Rxvt-unicodeRxvt-unicode Version6.3
Rxvt-unicodeRxvt-unicode Version7.0
Rxvt-unicodeRxvt-unicode Version7.1
Rxvt-unicodeRxvt-unicode Version7.2
Rxvt-unicodeRxvt-unicode Version7.3
Rxvt-unicodeRxvt-unicode Version7.4
Rxvt-unicodeRxvt-unicode Version7.5
Rxvt-unicodeRxvt-unicode Version7.6
Rxvt-unicodeRxvt-unicode Version7.7
Rxvt-unicodeRxvt-unicode Version7.8
Rxvt-unicodeRxvt-unicode Version7.9
Rxvt-unicodeRxvt-unicode Version8.0
Rxvt-unicodeRxvt-unicode Version8.1
Rxvt-unicodeRxvt-unicode Version8.2
Rxvt-unicodeRxvt-unicode Version8.3
Rxvt-unicodeRxvt-unicode Version8.4
Rxvt-unicodeRxvt-unicode Version8.5
Rxvt-unicodeRxvt-unicode Version8.5a
Rxvt-unicodeRxvt-unicode Version8.6
Rxvt-unicodeRxvt-unicode Version8.7
Rxvt-unicodeRxvt-unicode Version8.8
Rxvt-unicodeRxvt-unicode Version8.9
Rxvt-unicodeRxvt-unicode Version9.0
WtermWterm Version <= 6.2.8a2
WtermWterm Version6.2.5
WtermWterm Version6.2.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.169
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.7 1.9 6.4
AV:L/AC:H/Au:N/C:P/I:P/A:P