VYPR
High severity7.3NVD Advisory· Published Mar 3, 2003· Updated Apr 16, 2026

CVE-2003-0063

CVE-2003-0063

Description

The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

Affected products

6
  • Xorg/X11r66 versions
    cpe:2.3:a:xfree86_project:x11r6:4.0:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:xfree86_project:x11r6:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.2.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.