Known Vulnerabilities for products from Invisible-island

Listed below are 9 of the newest known vulnerabilities associated with the vendor "Invisible-island".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-50495 json 6.5 - MEDIUM 2023-12-12 2024-01-31
CVE-2023-40359 json xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alph... 9.8 - CRITICAL 2023-08-14 2023-09-07
CVE-2022-45063 json xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to c... Not Provided 2022-11-10 2026-04-08
CVE-2022-24130 json xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphic... 5.5 - MEDIUM 2022-01-31 2023-11-07
CVE-2021-27135 json xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) v... 9.8 - CRITICAL 2021-02-10 2023-11-07
CVE-2017-20229 json MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code ... Not Provided 2026-03-28 2026-04-02
CVE-2008-2383 json CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters... 9.3 - HIGH 2009-01-02 2023-11-07
CVE-2006-7236 json The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which all... 9.3 - HIGH 2009-01-02 2018-10-03
CVE-2005-3120 json Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary ... Not Provided 2005-10-17 2025-04-03

Known software with vulnerabilities from Invisible-island

Type Vendor Product Version
ApplicationInvisible-islandXterm215