CVE-2017-10684: Invisible-Island Ncurses
Critical severity, CVSS 9.8. EPSS: 4.9% chance of exploitation in the next 30 days.
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
Affected products
- Invisible-Island Ncurses: version 6.0 only
Published 2017-06-29. Last modified 2026-07-23.