Vulnerabilities > GNU > Screen > 3.9.9

DATE CVE VULNERABILITY TITLE RISK
2021-02-09 CVE-2021-26937 Argument Injection or Modification vulnerability in multiple products
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
network
low complexity
gnu debian fedoraproject CWE-88
critical
9.8
2020-02-24 CVE-2020-9366 Out-of-bounds Write vulnerability in GNU Screen
A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49.
network
low complexity
gnu CWE-787
7.5
2017-03-20 CVE-2017-5618 Incorrect Authorization vulnerability in GNU Screen
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
local
low complexity
gnu CWE-863
7.2
2006-10-24 CVE-2006-4573 Denial of Service vulnerability in GNU Screen
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.
network
high complexity
gnu
2.6
2003-12-15 CVE-2003-0972 Unspecified vulnerability in GNU Screen
Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.
network
low complexity
gnu
critical
10.0
2002-04-23 CVE-2002-1602 Buffer Overflow vulnerability in GNU Screen Braille Module
Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.
local
low complexity
gnu
4.6