Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Invisible Island

First CVE: —Active for: N/ATotal CVEs: 37

Invisible Island maintains a focused portfolio of widely-used open-source terminal and utility software, including xterm, lynx, mawk, and ncurses libraries, that are embedded across Unix/Linux systems and applications despite their narrow product range. These components are foundational to text-based interfaces and system administration workflows, giving their vulnerability footprint significance beyond volume. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Invisible Island over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Mar 28, 2026
122 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-3120CRITICAL
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian chara
Oct 17, 20059.853NOYES
CVE-2006-7236HIGH
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code o
Jan 2, 20099.340NOYES
CVE-2022-45063CRITICAL
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh
Nov 10, 20229.834NONO
CVE-2021-27135CRITICAL
xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.
Feb 10, 20219.833NONO
CVE-2017-20229CRITICAL
MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-suppli
Mar 28, 20269.832NONO
CVE-2021-39537HIGH
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
Sep 20, 20218.832NONO
CVE-2017-10684CRITICAL
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
Jun 29, 20179.830NONO
CVE-2017-10685CRITICAL
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
Jun 29, 20179.829NONO
CVE-2023-29491HIGH
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file tha
Apr 14, 20237.828NONO
CVE-2017-16879HIGH
Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly exec
Nov 22, 20177.828NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
49%
32%
19%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (18.9%)
Network26 (70.3%)
Unknown4 (10.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (89.2%)
High0 (0.0%)
Unknown4 (10.8%)
User Interaction
None12 (32.4%)
Unknown4 (10.8%)
Required21 (56.8%)
Privileges Required
Low2 (5.4%)
High0 (0.0%)
None31 (83.8%)
Unknown4 (10.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Invisible Island.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Invisible Island — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Invisible Island's Products

View all 3 CNAs →

Top CWEs