Vulnerabilities
Vulnerable Software
Tigervnc:  >> Tigervnc  >> 1.1  Security Vulnerabilities
Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.
CVSS Score
9.8
EPSS Score
0.032
Published
2017-02-28
The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.
CVSS Score
5.8
EPSS Score
0.005
Published
2011-05-26


Contact Us

Shodan ® - All rights reserved