Invisible Island maintains a focused portfolio of widely-used open-source terminal and utility software, including xterm, lynx, mawk, and ncurses libraries, that are embedded across Unix/Linux systems and applications despite their narrow product range. These components are foundational to text-based interfaces and system administration workflows, giving their vulnerability footprint significance beyond volume. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Invisible Island over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3120CRITICAL Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian chara | Oct 17, 2005 | 9.8 | 53 | NO | YES |
CVE-2006-7236HIGH The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code o | Jan 2, 2009 | 9.3 | 40 | NO | YES |
CVE-2022-45063CRITICAL xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh | Nov 10, 2022 | 9.8 | 34 | NO | NO |
CVE-2021-27135CRITICAL xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence. | Feb 10, 2021 | 9.8 | 33 | NO | NO |
CVE-2017-20229CRITICAL MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-suppli | Mar 28, 2026 | 9.8 | 32 | NO | NO |
CVE-2021-39537HIGH An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow. | Sep 20, 2021 | 8.8 | 32 | NO | NO |
CVE-2017-10684CRITICAL In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack. | Jun 29, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-10685CRITICAL In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack. | Jun 29, 2017 | 9.8 | 29 | NO | NO |
CVE-2023-29491HIGH ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file tha | Apr 14, 2023 | 7.8 | 28 | NO | NO |
CVE-2017-16879HIGH Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly exec | Nov 22, 2017 | 7.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Invisible Island.
Media articles that mention a CVE ID that affects a product developed by Invisible Island — matched by CVE ID, not by vendor name.