Vulnerabilities > Tigervnc > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-18 | CVE-2024-0408 | A flaw was found in the X.Org server. | 5.5 |
2019-12-26 | CVE-2019-15695 | Improper Check for Unusual or Exceptional Conditions vulnerability in multiple products TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. | 6.5 |
2019-12-26 | CVE-2019-15694 | Out-of-bounds Write vulnerability in multiple products TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. | 6.5 |
2017-04-01 | CVE-2017-7396 | Missing Release of Resource after Effective Lifetime vulnerability in Tigervnc 1.7.1 In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server. | 5.0 |
2017-04-01 | CVE-2017-7395 | Integer Overflow or Wraparound vulnerability in Tigervnc 1.7.1 In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server. | 4.0 |
2017-04-01 | CVE-2017-7394 | Improper Input Validation vulnerability in Tigervnc 1.7.1 In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames. | 5.0 |
2017-04-01 | CVE-2017-7393 | Double Free vulnerability in Tigervnc 1.7.1 In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution. | 6.5 |
2017-04-01 | CVE-2017-7392 | Missing Release of Resource after Effective Lifetime vulnerability in Tigervnc 1.7.1 In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server. | 5.0 |
2017-02-28 | CVE-2017-5581 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tigervnc Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries. | 6.8 |
2017-02-28 | CVE-2016-10207 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early. | 5.0 |