Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2019-15695
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability occurs due to insufficient sanitization of PixelFormat. Since remote attacker can choose offset from start of the buffer to start writing his values, exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.
0
Attacker Value
Unknown
CVE-2017-7393
Disclosure Date: April 01, 2017 (last updated November 26, 2024)
In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
0
Attacker Value
Unknown
CVE-2017-7395
Disclosure Date: April 01, 2017 (last updated November 26, 2024)
In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.
0
Attacker Value
Unknown
CVE-2017-7396
Disclosure Date: April 01, 2017 (last updated November 26, 2024)
In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.
0
Attacker Value
Unknown
CVE-2017-7394
Disclosure Date: April 01, 2017 (last updated November 26, 2024)
In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.
0
Attacker Value
Unknown
CVE-2017-7392
Disclosure Date: April 01, 2017 (last updated November 26, 2024)
In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.
0
Attacker Value
Unknown
CVE-2016-10207
Disclosure Date: February 28, 2017 (last updated November 26, 2024)
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
0
Attacker Value
Unknown
CVE-2017-5581
Disclosure Date: February 28, 2017 (last updated November 26, 2024)
Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.
0
Attacker Value
Unknown
CVE-2014-8241
Disclosure Date: December 14, 2016 (last updated November 25, 2024)
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
0
Attacker Value
Unknown
CVE-2014-8240
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.
0