Записи iTerm2
12 опубликованных записей вендора iterm2.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 8,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-116 Improper Encoding or Escaping of Output2
- CWE-117 Improper Output Neutralization for Logs2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data1
- CWE-532 Insertion of Sensitive Information into Log File1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-9535Эксплойта нет | iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command executioniterm2 · iterm2 · CWE-349 | Критическая9,8 | — | 2,5 % | 9 окт. 2019 г. |
40В плане | CVE-2024-38396Proof of concept | An issue was discovered in iTerm2 3.5.x before 3.5.2.iterm2 · iterm2 · CWE-94 | Критическая9,8 | — | 1,7 % | 16 июн. 2024 г. |
39Наблюдать | CVE-2024-38395Эксплойта нет | In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is noiterm2 · iterm2 · CWE-94 | Критическая9,8 | — | 1,5 % | 15 июн. 2024 г. |
39Наблюдать | CVE-2023-46300Эксплойта нет | iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integratioiterm2 · iterm2 · CWE-116 | Критическая9,8 | — | 1,2 % | 22 окт. 2023 г. |
39Наблюдать | CVE-2023-46301Эксплойта нет | iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.iterm2 · iterm2 · CWE-116 | Критическая9,8 | — | 1,2 % | 22 окт. 2023 г. |
39Наблюдать | CVE-2022-45872Эксплойта нет | iTerm2 before 3.4.18 mishandles a DECRQSS response.iterm2 · iterm2 · CWE-20 | Критическая9,8 | — | 0,9 % | 23 нояб. 2022 г. |
39Наблюдать | CVE-2023-46321Эксплойта нет | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.iterm2 · iterm2 · CWE-117 | Критическая9,8 | — | 0,7 % | 22 окт. 2023 г. |
39Наблюдать | CVE-2023-46322Эксплойта нет | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.iterm2 · iterm2 · CWE-117 | Критическая9,8 | — | 0,7 % | 22 окт. 2023 г. |
37Наблюдать | CVE-2025-22275Эксплойта нет | iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by readiniterm2 · iterm2 · CWE-532 | Критическая9,3 | — | 0,5 % | 3 янв. 2025 г. |
31Наблюдать | CVE-2015-9231Эксплойта нет | iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries.iterm2 · iterm2 · CWE-200 | Высокая7,5 | — | 2,2 % | 20 сент. 2017 г. |
31Наблюдать | CVE-2026-41253Эксплойта нет | In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains aiterm2 · iterm2 · CWE-829 | Высокая7,8 | — | 0,2 % | 18 апр. 2026 г. |
30Наблюдать | CVE-2019-19022Эксплойта нет | iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which miterm2 · iterm2 · CWE-200 | Высокая7,5 | — | 1,4 % | 17 нояб. 2019 г. |
- CVE-2019-953540В плане
iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %iterm2 · iterm29 окт. 2019 г.
- CVE-2024-3839640В плане
An issue was discovered in iTerm2 3.5.x before 3.5.2.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %iterm2 · iterm216 июн. 2024 г.
- CVE-2024-3839539Наблюдать
In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is no
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iterm2 · iterm215 июн. 2024 г.
- CVE-2023-4630039Наблюдать
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integratio
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iterm2 · iterm222 окт. 2023 г.
- CVE-2023-4630139Наблюдать
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iterm2 · iterm222 окт. 2023 г.
- CVE-2022-4587239Наблюдать
iTerm2 before 3.4.18 mishandles a DECRQSS response.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iterm2 · iterm223 нояб. 2022 г.
- CVE-2023-4632139Наблюдать
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iterm2 · iterm222 окт. 2023 г.
- CVE-2023-4632239Наблюдать
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iterm2 · iterm222 окт. 2023 г.
- CVE-2025-2227537Наблюдать
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by readin
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %iterm2 · iterm23 янв. 2025 г.
- CVE-2015-923131Наблюдать
iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %iterm2 · iterm220 сент. 2017 г.
- CVE-2026-4125331Наблюдать
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %iterm2 · iterm218 апр. 2026 г.
- CVE-2019-1902230Наблюдать
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which m
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %iterm2 · iterm217 нояб. 2019 г.