Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bruno Vernay

#13417of 53,633
19.8Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2020-6935
10
2020-08-04
Ncurses · Ncurses · CVE-2021-39537
**Name of the Vulnerable Software and Affected Versions** ncurses versions through v6.2-1 **Description** An issue was discovered in the ncurses library, specifically in the ` nc captoinfo` function of the `captoinfo.c` component, which is related to a heap-based buffer overflow. This issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. **Recommendations** For ncurses versions through v6.2-1, as a temporary workaround, consider disabling the ` nc captoinfo` function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2020-14690
9.8
2020-07-21
Lua · Lua · CVE-2020-15889
**Name of the Vulnerable Software and Affected Versions** Lua version 5.4.0 **Description** The issue is related to a heap-based buffer over-read in the `getobjname` function. This occurs because `youngcollection` in `lgc.c` uses `markold` for an insufficient number of list members. **Recommendations** For Lua version 5.4.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.