{"id":"CVE-2014-3121","details":"rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.","modified":"2026-04-16T06:22:00.966735943Z","published":"2014-05-14T00:55:10Z","related":["openSUSE-SU-2024:10526-1"],"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-2925"},{"type":"WEB","url":"http://dist.schmorp.de/rxvt-unicode/Changes"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00026.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2014-06/msg00038.html"},{"type":"WEB","url":"http://seclists.org/oss-sec/2014/q2/204"},{"type":"WEB","url":"http://www.securityfocus.com/bid/67155"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133166.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133195.html"}],"schema_version":"1.7.5"}