CVE-2014-3121

rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.

Published: 2014-05-14 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-3121 is rated Moderate Risk (60.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 3.34%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2014-3121

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-12-28 3.92% 3.34% -0.58%
2 2025-10-22 4.16% 3.92% -0.24%
3 2025-03-30 4.16%

Full EPSS history (9 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-3121

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.6 2.0 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:H)
Exploitation requires uncommon or highly specific conditions.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
4.9 10.0 [email protected]

Weakness enumeration for CVE-2014-3121

OS Trackers for CVE-2014-3121

vendor priority summary link
debian not yet assigned CVE-2014-3121 not yet assigned priority: Debian including 1 source packages (rxvt-unicode), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2014-3121
gentoo normal CVE-2014-3121: 1 GLSA(s) (201406-18), 1 atom(s) (x11-terms/rxvt-unicode); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2014-3121
ubuntu medium CVE-2014-3121 medium priority: Ubuntu including 1 source packages (rxvt-unicode), 16 status rows across 16 suites (artful, bionic, cosmic, disco, lucid, precise, quantal, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): not-affected 10, ignored 4, DNE 1, released 1. https://ubuntu.com/security/CVE-2014-3121

Affected software / configurations for CVE-2014-3121

Vendor Product Version Raw CPE
marc_lehmann rxvt-unicode <= 9.19 cpe:2.3:a:marc_lehmann:rxvt-unicode:*:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.0 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.0:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.01 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.01:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.02 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.02:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.05 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.05:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.06 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.06:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.07 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.07:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.08 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.08:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.09 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.09:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.10 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.10:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.11 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.11:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.12 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.12:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.14 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.14:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.15 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.15:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.16 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.16:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.17 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.17:*:*:*:*:*:*:*
marc_lehmann rxvt-unicode 9.18 cpe:2.3:a:marc_lehmann:rxvt-unicode:9.18:*:*:*:*:*:*:*

References for CVE-2014-3121

cvelogic Threat Intelligence