Vulnerabilities > Tigervnc > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-01-02 CVE-2014-0011 Out-of-bounds Write vulnerability in Tigervnc
Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.
network
low complexity
tigervnc CWE-787
critical
9.8
2017-02-28 CVE-2017-5581 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tigervnc
Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.
network
low complexity
tigervnc CWE-119
critical
9.8
2016-12-14 CVE-2014-8241 NULL Pointer Dereference vulnerability in multiple products
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
network
low complexity
tigervnc redhat CWE-476
critical
9.8