Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Iterm2 HIGH 7.8
CVE-2026-41253

In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a maliciou…

Fix: after 3.6.9
Fix from $1,950 2026-04-18
Iterm2 CRITICAL 9.3
CVE-2025-22275

iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tm…

Fix: 3.5.11+
Fix from $2,300 2025-01-03
Iterm2 CRITICAL 9.8
CVE-2024-38396

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in…

Fix: 3.5.2+
Fix from $2,300 2024-06-16
Iterm2 CRITICAL 9.8
CVE-2024-38395

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivial…

Fix: 3.5.2+
Fix from $2,300 2024-06-16
Iterm2 CRITICAL 9.8
CVE-2023-46321

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man…

Fix: after 3.4.21
Fix from $2,300 2023-10-23
Iterm2 CRITICAL 9.8
CVE-2023-46322

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric…

Fix: after 3.4.21
Fix from $2,300 2023-10-23
Iterm2 CRITICAL 9.8
CVE-2023-46300

iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.

Fix: 3.4.20+
Fix from $2,300 2023-10-22
Iterm2 CRITICAL 9.8
CVE-2023-46301

iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.

Fix: 3.4.20+
Fix from $2,300 2023-10-22
Iterm2 CRITICAL 9.8
CVE-2022-45872

iTerm2 before 3.4.18 mishandles a DECRQSS response.

Fix: 3.4.18+
Fix from $2,300 2022-11-23
Iterm2 HIGH 7.5
CVE-2019-19022

iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allo…

Fix: after 3.3.6
Fix from $1,950 2019-11-17
Iterm2 CRITICAL 9.8
CVE-2019-9535

A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by provi…

Fix: after 3.3.5
Fix from $2,300 2019-10-09
Iterm2 HIGH 7.5
CVE-2015-9231

iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature was added to iTerm2 version 3.0…

Patch available
Fix from $1,950 2017-09-20