Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.042
EPSS Ranking 89.8%