Filtered by vendor Tigervnc
Subscribe
Total
29 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-7392 | 1 Tigervnc | 1 Tigervnc | 2019-10-03 | 5.0 MEDIUM | 7.5 HIGH |
In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server. | |||||
CVE-2017-7396 | 1 Tigervnc | 1 Tigervnc | 2019-10-03 | 5.0 MEDIUM | 7.5 HIGH |
In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server. | |||||
CVE-2016-10207 | 2 Opensuse, Tigervnc | 2 Leap, Tigervnc | 2018-02-01 | 5.0 MEDIUM | 7.5 HIGH |
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early. | |||||
CVE-2017-7395 | 1 Tigervnc | 1 Tigervnc | 2018-01-13 | 4.0 MEDIUM | 6.5 MEDIUM |
In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server. | |||||
CVE-2017-7394 | 1 Tigervnc | 1 Tigervnc | 2018-01-13 | 5.0 MEDIUM | 7.5 HIGH |
In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames. | |||||
CVE-2017-7393 | 1 Tigervnc | 1 Tigervnc | 2018-01-13 | 6.5 MEDIUM | 8.8 HIGH |
In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution. | |||||
CVE-2017-5581 | 1 Tigervnc | 1 Tigervnc | 2018-01-05 | 6.8 MEDIUM | 9.8 CRITICAL |
Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries. | |||||
CVE-2014-8240 | 1 Tigervnc | 1 Tigervnc | 2017-09-08 | 7.5 HIGH | N/A |
Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051. | |||||
CVE-2014-8241 | 2 Redhat, Tigervnc | 5 Enterprise Linux Desktop, Enterprise Linux Hpc Node, Enterprise Linux Server and 2 more | 2016-12-20 | 7.5 HIGH | 9.8 CRITICAL |
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052. |