Ncurses is a widely embedded terminal-control library used across Unix and Linux systems for cursor positioning, color handling, and text-rendering in command-line interfaces, where its small product footprint masks deep distribution through countless downstream applications and system tools. Its observed vulnerability pattern centers on memory-buffer handling and format-string issues, reflecting the low-level I/O and string-processing operations intrinsic to terminal control. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ncurses Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15548CRITICAL An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled. | Aug 26, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-15547HIGH An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled. | Aug 26, 2019 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ncurses Project.
Media articles that mention a CVE ID that affects a product developed by Ncurses Project — matched by CVE ID, not by vendor name.