Vulnerability Details CVE-2014-0011
Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 72.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2014-0011
-
cpe:2.3:a:tigervnc:tigervnc:-
-
cpe:2.3:a:tigervnc:tigervnc:0.0.90
-
cpe:2.3:a:tigervnc:tigervnc:0.0.91
-
cpe:2.3:a:tigervnc:tigervnc:1.0
-
cpe:2.3:a:tigervnc:tigervnc:1.0.0
-
cpe:2.3:a:tigervnc:tigervnc:1.0.1
-
cpe:2.3:a:tigervnc:tigervnc:1.0.90
-
cpe:2.3:a:tigervnc:tigervnc:1.1
-
cpe:2.3:a:tigervnc:tigervnc:1.1.0
-
cpe:2.3:a:tigervnc:tigervnc:1.1.90
-
cpe:2.3:a:tigervnc:tigervnc:1.2.0
-
cpe:2.3:a:tigervnc:tigervnc:1.2.90
-
cpe:2.3:a:tigervnc:tigervnc:1.3