Vulnerabilities > Tigervnc > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-01 CVE-2017-7394 Improper Input Validation vulnerability in Tigervnc 1.7.1
In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.
network
low complexity
tigervnc CWE-20
7.5
2017-04-01 CVE-2017-7393 Double Free vulnerability in Tigervnc 1.7.1
In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
network
low complexity
tigervnc CWE-415
8.8
2017-04-01 CVE-2017-7392 Missing Release of Resource after Effective Lifetime vulnerability in Tigervnc 1.7.1
In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.
network
low complexity
tigervnc CWE-772
7.5
2017-02-28 CVE-2016-10207 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
network
low complexity
opensuse tigervnc CWE-119
7.5