Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mawk CRITICAL 9.8
CVE-2017-20229

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate…

Fix: after 1.3.3-17
Fix from $2,300 2026-03-28
Ncurses HIGH 7.8
CVE-2025-69720

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

Fix: after 6.4
Fix from $1,950 2026-03-19
Ncurse MEDIUM 6.5
CVE-2023-50495

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Patch available
Fix from $1,600 2023-12-12
Ncurses MEDIUM 6.5
CVE-2020-19190

Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via craft…

No fix yet
Fix from $1,600 2023-08-22
Ncurses MEDIUM 6.5
CVE-2020-19188

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service vi…

No fix yet
Fix from $1,600 2023-08-22
Ncurses MEDIUM 6.5
CVE-2020-19187

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service vi…

No fix yet
Fix from $1,600 2023-08-22
Ncurses MEDIUM 6.5
CVE-2020-19186

Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service …

No fix yet
Fix from $1,600 2023-08-22
Ncurses MEDIUM 6.5
CVE-2020-19185

Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of serv…

No fix yet
Fix from $1,600 2023-08-22
Xterm CRITICAL 9.8
CVE-2023-40359

xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore)…

Fix: 380+
Fix from $2,300 2023-08-14
Ncurses HIGH 7.8
CVE-2023-29491

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data …

Fix: 6.4+
Fix from $1,950 2023-04-14
Ncurses HIGH 8.8
CVE-2021-39537

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

Fix: after 6.2.1
Fix from $1,950 2021-09-20
Ncurses MEDIUM 5.4
CVE-2019-17595

There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

Fix: 6.2+
Fix from $1,600 2019-10-14
Ncurses MEDIUM 5.3
CVE-2019-17594

There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

Fix: 6.2+
Fix from $1,600 2019-10-14
Ncurses MEDIUM 6.5
CVE-2018-19217

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. …

No fix yet
Fix from $1,600 2018-11-12
Ncurses MEDIUM 5.5
CVE-2018-19211

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The pr…

No fix yet
Fix from $1,600 2018-11-12
Ncurses HIGH 7.8
CVE-2017-16879

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (appl…

No fix yet
Fix from $1,950 2017-11-22
Ncurses HIGH 7.5
CVE-2017-13728

There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of…

No fix yet
Fix from $1,950 2017-08-29
Ncurses MEDIUM 6.5
CVE-2017-13729

There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack.

No fix yet
Fix from $1,600 2017-08-29
Ncurses MEDIUM 6.5
CVE-2017-13730

There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of servic…

No fix yet
Fix from $1,600 2017-08-29
Ncurses MEDIUM 6.5
CVE-2017-13731

There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service…

No fix yet
Fix from $1,600 2017-08-29
Ncurses MEDIUM 6.5
CVE-2017-13732

There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service att…

No fix yet
Fix from $1,600 2017-08-29
Ncurses MEDIUM 6.5
CVE-2017-13733

There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attac…

No fix yet
Fix from $1,600 2017-08-29
Ncurses MEDIUM 6.5
CVE-2017-13734

There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.

Patch available
Fix from $1,600 2017-08-29
Ncurses HIGH 7.5
CVE-2017-11112

In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial o…

Mitigation only
Fix from $1,950 2017-07-08
Ncurses HIGH 7.5
CVE-2017-11113

In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of servi…

No fix yet
Fix from $1,950 2017-07-08
Ncurses CRITICAL 9.8
CVE-2017-10684

In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution atta…

Mitigation only
Fix from $2,300 2017-06-29
Ncurses CRITICAL 9.8
CVE-2017-10685

In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution atta…

Mitigation only
Fix from $2,300 2017-06-29
Xterm HIGH 9.3
CVE-2006-7236EPSS 7%

The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attack…

Mitigation only
Fix from $1,950 2009-01-02
Xterm HIGH 9.3
CVE-2008-2383

CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command n…

Mitigation only
Fix from $1,950 2009-01-02