The Curses Project maintains a terminal-control library that provides low-level cursor positioning and display formatting for console applications, a narrowly scoped but foundational component embedded across Unix and Linux system utilities. Observed vulnerabilities in this library center on missing encryption of sensitive data, reflecting the cleartext nature of terminal I/O and authentication handling within terminal-based tools.
The number and severity of CVEs published that impact products developed by Curses Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10615HIGH curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It ma | Jun 1, 2018 | 8.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Curses Project.
Media articles that mention a CVE ID that affects a product developed by Curses Project — matched by CVE ID, not by vendor name.