Vulnerabilities > GNU > Ncurses

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2017-13728 Infinite Loop vulnerability in GNU Ncurses 6.0
There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic.
network
low complexity
gnu CWE-835
7.5
2017-07-08 CVE-2017-11113 NULL Pointer Dereference vulnerability in GNU Ncurses 6.0
In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c.
network
low complexity
gnu CWE-476
7.5
2017-07-08 CVE-2017-11112 Improper Input Validation vulnerability in GNU Ncurses 6.0
In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c.
network
low complexity
gnu CWE-20
7.5
2017-06-29 CVE-2017-10685 Use of Externally-Controlled Format String vulnerability in GNU Ncurses 6.0
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function.
network
low complexity
gnu CWE-134
critical
9.8
2017-06-29 CVE-2017-10684 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function.
network
low complexity
gnu CWE-119
critical
9.8