ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-15548
+1 in the same advisory: …15547
An issue was discovered in the ncurses crate through 5.99.0 for Rust.

An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.

NVD description · AI analysis pending
9.8
group max
2%
  • ncurses project ncurses
CVE-2019-15546
An issue was discovered in the pancurses crate through 0.16.1 for Rust.

An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities.

NVD description · AI analysis pending
7.51%
  • pancurses project pancurses
CVE-2016-10615
curses is bindings for the native curses library, a full featured console IO library.

curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

NVD description · AI analysis pending
8.12%
  • curses project curses