Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown

CVE-2020-14403

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
Attacker Value
Unknown

CVE-2020-14398

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
Attacker Value
Unknown

CVE-2020-14400

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
Attacker Value
Unknown

CVE-2020-14401

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
Attacker Value
Unknown

CVE-2019-20840

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.
Attacker Value
Unknown

CVE-2020-14404

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
Attacker Value
Unknown

CVE-2020-14405

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
Attacker Value
Unknown

CVE-2019-20788

Disclosure Date: April 23, 2020 (last updated February 21, 2025)
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
Attacker Value
Unknown

CVE-2010-5304

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.
Attacker Value
Unknown

CVE-2019-15681

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a.