VulnerabilityDeferred
CVE-2024-37535
GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476.
MEDIUM 4.4EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2024/06/09/1
- http://www.openwall.com/lists/oss-security/2024/06/09/2
- https://gitlab.gnome.org/GNOME/vte/-/issues/2786
- https://gitlab.gnome.org/GNOME/vte/-/tags/0.76.3
- http://www.openwall.com/lists/oss-security/2024/06/09/1
- http://www.openwall.com/lists/oss-security/2024/06/09/2
- https://gitlab.gnome.org/GNOME/vte/-/issues/2786
- https://gitlab.gnome.org/GNOME/vte/-/tags/0.76.3
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.