İçeriğe atla
Noroxi

iTerm2 kayıtları

iterm2 üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%8,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

12 kayıt
  • CVE-2019-9535
    40Planlayın

    iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution

    KritikCVSS 9,8İstismar yokEPSS %2

    iterm2 · iterm29 Eki 2019

  • CVE-2024-38396
    40Planlayın

    An issue was discovered in iTerm2 3.5.x before 3.5.2.

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    iterm2 · iterm216 Haz 2024

  • CVE-2024-38395
    39İzleyin

    In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is no

    KritikCVSS 9,8İstismar yokEPSS %1

    iterm2 · iterm215 Haz 2024

  • CVE-2023-46300
    39İzleyin

    iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integratio

    KritikCVSS 9,8İstismar yokEPSS %1

    iterm2 · iterm222 Eki 2023

  • CVE-2023-46301
    39İzleyin

    iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.

    KritikCVSS 9,8İstismar yokEPSS %1

    iterm2 · iterm222 Eki 2023

  • CVE-2022-45872
    39İzleyin

    iTerm2 before 3.4.18 mishandles a DECRQSS response.

    KritikCVSS 9,8İstismar yokEPSS %1

    iterm2 · iterm223 Kas 2022

  • CVE-2023-46321
    39İzleyin

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.

    KritikCVSS 9,8İstismar yokEPSS %1

    iterm2 · iterm222 Eki 2023

  • CVE-2023-46322
    39İzleyin

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.

    KritikCVSS 9,8İstismar yokEPSS %1

    iterm2 · iterm222 Eki 2023

  • CVE-2025-22275
    37İzleyin

    iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by readin

    KritikCVSS 9,3İstismar yokEPSS %1

    iterm2 · iterm23 Oca 2025

  • CVE-2015-9231
    31İzleyin

    iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries.

    YüksekCVSS 7,5İstismar yokEPSS %2

    iterm2 · iterm220 Eyl 2017

  • CVE-2026-41253
    31İzleyin

    In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a

    YüksekCVSS 7,8İstismar yokEPSS %0

    iterm2 · iterm218 Nis 2026

  • CVE-2019-19022
    30İzleyin

    iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which m

    YüksekCVSS 7,5İstismar yokEPSS %1

    iterm2 · iterm217 Kas 2019