Show filters
32 Total Results
Displaying 11-20 of 32
Sort by:
Attacker Value
Unknown
CVE-2019-17595
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
0
Attacker Value
Unknown
CVE-2019-15548
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.
0
Attacker Value
Unknown
CVE-2019-15546
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities.
0
Attacker Value
Unknown
CVE-2019-15547
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled.
0
Attacker Value
Unknown
CVE-2018-19217
Disclosure Date: November 12, 2018 (last updated November 08, 2023)
In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party
0
Attacker Value
Unknown
CVE-2018-19211
Disclosure Date: November 12, 2018 (last updated November 27, 2024)
In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
0
Attacker Value
Unknown
CVE-2016-10615
Disclosure Date: June 01, 2018 (last updated November 26, 2024)
curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown
CVE-2017-16879
Disclosure Date: November 22, 2017 (last updated November 08, 2023)
Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.
0
Attacker Value
Unknown
CVE-2017-13733
Disclosure Date: August 29, 2017 (last updated November 08, 2023)
There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
0
Attacker Value
Unknown
CVE-2017-13734
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.
0