Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2016-10207
Disclosure Date: February 28, 2017 (last updated November 26, 2024)
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
0
Attacker Value
Unknown
CVE-2014-8240
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.
0
Attacker Value
Unknown
CVE-2011-1775
Disclosure Date: May 26, 2011 (last updated October 04, 2023)
The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.
0