Vulnerabilities
Vulnerable Software
Tigervnc:  >> Tigervnc  Security Vulnerabilities
In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
CVSS Score
8.8
EPSS Score
0.015
Published
2017-04-01
In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.
CVSS Score
7.5
EPSS Score
0.028
Published
2017-04-01
In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.
CVSS Score
6.5
EPSS Score
0.005
Published
2017-04-01
In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.
CVSS Score
7.5
EPSS Score
0.005
Published
2017-04-01
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
CVSS Score
7.5
EPSS Score
0.017
Published
2017-02-28
Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.
CVSS Score
9.8
EPSS Score
0.025
Published
2017-02-28
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
CVSS Score
9.8
EPSS Score
0.004
Published
2016-12-14
Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.
CVSS Score
7.5
EPSS Score
0.014
Published
2014-10-16
The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.
CVSS Score
5.8
EPSS Score
0.006
Published
2011-05-26


Contact Us

Shodan ® - All rights reserved