VYPR
Vendor

ncurses

Products
1
CVEs
14
Across products
14
Status
Private

Products

1

Recent CVEs

14
  • CVE-2021-39537HigSep 20, 2021
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

  • CVE-2023-29491HigApr 14, 2023
    risk 0.51cvss 7.8epss 0.01

    ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

  • CVE-2025-69720HigMar 19, 2026
    risk 0.47cvss 7.3epss 0.00

    The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

  • CVE-2022-29458HigApr 18, 2022
    risk 0.46cvss 7.1epss 0.01

    ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

  • CVE-2023-50495MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.01

    NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

  • CVE-2020-19190MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19189MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19188MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19187MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19186MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19185MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2018-19211MedNov 12, 2018
    risk 0.36cvss 5.5epss 0.01

    In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

  • CVE-2019-17595MedOct 14, 2019
    risk 0.28cvss 5.4epss 0.02

    There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

  • CVE-2019-17594MedOct 14, 2019
    risk 0.27cvss 5.3epss 0.01

    There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.