Possible RCE via stack-based buffer overflow in the fmt_entry function (CVE-2017-10684).
Possible RCE with format string vulnerability in the fmt_entry function (CVE-2017-10685).
Illegal address access in append_acs (CVE-2017-11112).
Dereferencing NULL pointer in ncparse_entry (CVE-2017-11113).
Fix infinite loop in the nextchar function in compscan.c (CVE-2017-13728).
Fix illegal address access in the ncsave_str (CVE-2017-13729).
Fix illegal address access in the function ncreadentrysource() (CVE-2017-13730).
Fix illegal address access in the function postprocess_termcap() (CVE-2017-13731).
Fix illegal address access in the function dump_uses() (CVE-2017-13732).
Fix illegal address access in the fmt_entry function (CVE-2017-13733).
Fix stack-based buffer overflow in the ncwrite_entry() function (CVE-2017-16879).