CVE-2023-40359: Invisible-Island Xterm
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.
Affected products
- Invisible-Island Xterm: before 380 (fixed in 380)
Published 2023-08-14. Last modified 2026-06-17.