Vulnerabilities > GNU > Ncurses > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2017-13734 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.
network
gnu CWE-119
4.3
2017-08-29 CVE-2017-13733 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13732 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13731 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13730 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13729 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0.
network
low complexity
gnu CWE-119
6.5
2017-07-08 CVE-2017-11113 NULL Pointer Dereference vulnerability in GNU Ncurses 6.0
In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c.
network
low complexity
gnu CWE-476
5.0
2017-07-08 CVE-2017-11112 Improper Input Validation vulnerability in GNU Ncurses 6.0
In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c.
network
low complexity
gnu CWE-20
5.0