Yes, I was thinking of iTerm2. "Older" means not the latest release and "buggy" includes well-intentioned vulnerabilities.

Sure. 3.6.9 (which was affected) was the most recent iTerm2 when that CVE came out.

Hence "or"