iTerm2 kayıtları
iterm2 üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %8,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-116 Improper Encoding or Escaping of Output2
- CWE-117 Improper Output Neutralization for Logs2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data1
- CWE-532 Insertion of Sensitive Information into Log File1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-9535İstismar yok | iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command executioniterm2 · iterm2 · CWE-349 | Kritik9,8 | — | %2,5 | 9 Eki 2019 |
40Planlayın | CVE-2024-38396Kavram kanıtı | An issue was discovered in iTerm2 3.5.x before 3.5.2.iterm2 · iterm2 · CWE-94 | Kritik9,8 | — | %1,7 | 16 Haz 2024 |
39İzleyin | CVE-2024-38395İstismar yok | In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is noiterm2 · iterm2 · CWE-94 | Kritik9,8 | — | %1,5 | 15 Haz 2024 |
39İzleyin | CVE-2023-46300İstismar yok | iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integratioiterm2 · iterm2 · CWE-116 | Kritik9,8 | — | %1,2 | 22 Eki 2023 |
39İzleyin | CVE-2023-46301İstismar yok | iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.iterm2 · iterm2 · CWE-116 | Kritik9,8 | — | %1,2 | 22 Eki 2023 |
39İzleyin | CVE-2022-45872İstismar yok | iTerm2 before 3.4.18 mishandles a DECRQSS response.iterm2 · iterm2 · CWE-20 | Kritik9,8 | — | %0,9 | 23 Kas 2022 |
39İzleyin | CVE-2023-46321İstismar yok | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.iterm2 · iterm2 · CWE-117 | Kritik9,8 | — | %0,7 | 22 Eki 2023 |
39İzleyin | CVE-2023-46322İstismar yok | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.iterm2 · iterm2 · CWE-117 | Kritik9,8 | — | %0,7 | 22 Eki 2023 |
37İzleyin | CVE-2025-22275İstismar yok | iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by readiniterm2 · iterm2 · CWE-532 | Kritik9,3 | — | %0,5 | 3 Oca 2025 |
31İzleyin | CVE-2015-9231İstismar yok | iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries.iterm2 · iterm2 · CWE-200 | Yüksek7,5 | — | %2,2 | 20 Eyl 2017 |
31İzleyin | CVE-2026-41253İstismar yok | In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains aiterm2 · iterm2 · CWE-829 | Yüksek7,8 | — | %0,2 | 18 Nis 2026 |
30İzleyin | CVE-2019-19022İstismar yok | iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which miterm2 · iterm2 · CWE-200 | Yüksek7,5 | — | %1,4 | 17 Kas 2019 |
- CVE-2019-953540Planlayın
iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution
KritikCVSS 9,8İstismar yokEPSS %2iterm2 · iterm29 Eki 2019
- CVE-2024-3839640Planlayın
An issue was discovered in iTerm2 3.5.x before 3.5.2.
KritikCVSS 9,8Kavram kanıtıEPSS %2iterm2 · iterm216 Haz 2024
- CVE-2024-3839539İzleyin
In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is no
KritikCVSS 9,8İstismar yokEPSS %1iterm2 · iterm215 Haz 2024
- CVE-2023-4630039İzleyin
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integratio
KritikCVSS 9,8İstismar yokEPSS %1iterm2 · iterm222 Eki 2023
- CVE-2023-4630139İzleyin
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.
KritikCVSS 9,8İstismar yokEPSS %1iterm2 · iterm222 Eki 2023
- CVE-2022-4587239İzleyin
iTerm2 before 3.4.18 mishandles a DECRQSS response.
KritikCVSS 9,8İstismar yokEPSS %1iterm2 · iterm223 Kas 2022
- CVE-2023-4632139İzleyin
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.
KritikCVSS 9,8İstismar yokEPSS %1iterm2 · iterm222 Eki 2023
- CVE-2023-4632239İzleyin
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.
KritikCVSS 9,8İstismar yokEPSS %1iterm2 · iterm222 Eki 2023
- CVE-2025-2227537İzleyin
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by readin
KritikCVSS 9,3İstismar yokEPSS %1iterm2 · iterm23 Oca 2025
- CVE-2015-923131İzleyin
iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries.
YüksekCVSS 7,5İstismar yokEPSS %2iterm2 · iterm220 Eyl 2017
- CVE-2026-4125331İzleyin
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a
YüksekCVSS 7,8İstismar yokEPSS %0iterm2 · iterm218 Nis 2026
- CVE-2019-1902230İzleyin
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which m
YüksekCVSS 7,5İstismar yokEPSS %1iterm2 · iterm217 Kas 2019