cbcvebase.

Gnu Ncurses vulnerabilities

31 known vulnerabilities affecting gnu/ncurses.

Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH9MEDIUM17LOW1UNKNOWN1

Vulnerabilities

Page 2 of 2
CVE-2020-19185P4MEDIUMCVSS 6.5≥ 0, < 6.1+20191019-12023-08-22
CVE-2020-19185 [MEDIUM] CVE-2020-19185: Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
osv
CVE-2017-13733P4MEDIUMCVSS 6.5≥ 0, < 6.0+20170902-12017-08-29
CVE-2017-13733 [MEDIUM] CVE-2017-13733: There is an illegal address access in the fmt_entry function in progs/dump_entry There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
osv
CVE-2017-13734P4MEDIUMCVSS 6.5≥ 0, < 6.0+20170827-12017-08-29
CVE-2017-13734 [MEDIUM] CVE-2017-13734: There is an illegal address access in the _nc_safe_strcat function in strings There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.
osv
CVE-2023-50495P4MEDIUMCVSS 6.5≥ 0, < 6.4+20230625-12023-12-12
CVE-2023-50495 [MEDIUM] CVE-2023-50495: NCurse v6 NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().
osv
CVE-2022-29458P4HIGHCVSS 7.1≥ 0, < 6.2+20201114-2+deb11u1≥ 0, < 6.3+20220423-12022-04-18
CVE-2022-29458 [HIGH] CVE-2022-29458: ncurses 6 ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
osv
CVE-2019-17595P4MEDIUMCVSS 5.4≥ 0, < 6.1+20191019-12019-10-14
CVE-2019-17595 [MEDIUM] CVE-2019-17595: There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
osv
CVE-2018-19217P4MEDIUMCVSS 6.5≥ 0, < 6.0+20170701-12018-11-12
CVE-2018-19217 [MEDIUM] CVE-2018-19217: In ncurses, possibly a 6 In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party
osv
CVE-2019-17594P4MEDIUMCVSS 5.3≥ 0, < 6.1+20191019-12019-10-14
CVE-2019-17594 [MEDIUM] CVE-2019-17594: There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
osv
CVE-2018-19211P4MEDIUMCVSS 5.5≥ 0, < 6.1+20180210-32018-11-12
CVE-2018-19211 [MEDIUM] CVE-2018-19211: In ncurses 6 In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
osv
CVE-2025-6141P4LOWCVSS 3.3v6.5-202503222025-06-16
CVE-2025-6141 [LOW] CWE-119 CVE-2025-6141: A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It i
nvdosv
CVE-2023-45918UNKNOWN≥ 0, < 6.4+20230625-12024-02-16
CVE-2023-45918 CVE-2023-45918: ncurses 6 ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c. NOTE: Multiple third parties have disputed this indicating upstream does not regard it as a security issue.
osv
Gnu Ncurses vulnerabilities | cvebase