Libvnc Project
Libvnc Project Libvncserver: vulnerabilidades y CVE
Libvnc Project Libvncserver tiene 24 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses0
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-14405 | Media (6.5) | 1.9% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size. |
| CVE-2020-14404 | Media (5.4) | 1.6% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings. |
| CVE-2020-14403 | Media (5.4) | 1.6% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings. |
| CVE-2020-14402 | Media (5.4) | 1.9% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings. |
| CVE-2020-14398 | Alta (7.5) | 2.8% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c. |
| CVE-2020-14397 | Alta (7.5) | 3.4% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference. |
| CVE-2020-14396 | Alta (7.5) | 2.6% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference. |
| CVE-2019-20840 | Alta (7.5) | 2.6% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode. |
| CVE-2019-20839 | Alta (7.5) | 3.6% | — | 17 jun 2020 | libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename. |
| CVE-2018-21247 | Alta (7.5) | 2.5% | — | 17 jun 2020 | An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function. |
| CVE-2019-20788 | Crítica (9.8) | 2.5% | — | 23 abr 2020 | libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690. |
| CVE-2019-15681 | Alta (7.5) | 2.9% | — | 29 oct 2019 | LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with… |
| CVE-2018-20750 | Crítica (9.8) | 3.3% | — | 30 ene 2019 | LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. |
| CVE-2018-20749 | Crítica (9.8) | 3.2% | — | 30 ene 2019 | LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. |
| CVE-2018-20748 | Crítica (9.8) | 3.3% | — | 30 ene 2019 | LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. |
| CVE-2018-6307 | Alta (8.1) | 27% | — | 19 dic 2018 | LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution. |
| CVE-2018-20024 | Alta (7.5) | 3.3% | — | 19 dic 2018 | LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS. |
| CVE-2018-20023 | Alta (7.5) | 2.5% | — | 19 dic 2018 | LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information… |
| CVE-2018-20022 | Alta (7.5) | 2.9% | — | 19 dic 2018 | LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for… |
| CVE-2018-20021 | Alta (7.5) | 3.5% | — | 19 dic 2018 | LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM |
| CVE-2018-20020 | Crítica (9.8) | 8.6% | — | 19 dic 2018 | LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution |
| CVE-2018-20019 | Crítica (9.8) | 9.5% | — | 19 dic 2018 | LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution |
| CVE-2018-15127 | Crítica (9.8) | 15% | — | 19 dic 2018 | LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution |
| CVE-2018-15126 | Crítica (9.8) | 12% | — | 19 dic 2018 | LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution |