Search CVE reports
11 – 17 of 17 results
CVE-2018-20748
Medium prioritySome fixes available 7 of 20
LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.
4 affected packages
italc, libvncserver, tightvnc, x11vnc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
italc | Not in release | Not in release | Not in release | Fixed | Fixed |
libvncserver | Not affected | Not affected | Not affected | Fixed | Fixed |
tightvnc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
x11vnc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-20022
Medium prioritySome fixes available 8 of 22
LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information...
5 affected packages
italc, libvncserver, ssvnc, tightvnc, x11vnc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
italc | Not in release | Not in release | Not in release | Fixed | Fixed |
libvncserver | Not affected | Not affected | Not affected | Fixed | Fixed |
ssvnc | Not affected | Not affected | Not affected | Vulnerable | Fixed |
tightvnc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
x11vnc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-20021
Medium prioritySome fixes available 8 of 22
LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
5 affected packages
italc, libvncserver, ssvnc, tightvnc, x11vnc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
italc | Not in release | Not in release | Not in release | Fixed | Fixed |
libvncserver | Not affected | Not affected | Not affected | Fixed | Fixed |
ssvnc | Not affected | Not affected | Not affected | Vulnerable | Fixed |
tightvnc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
x11vnc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-20020
Medium prioritySome fixes available 8 of 22
LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution
5 affected packages
italc, libvncserver, ssvnc, tightvnc, x11vnc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
italc | Not in release | Not in release | Not in release | Fixed | Fixed |
libvncserver | Not affected | Not affected | Not affected | Fixed | Fixed |
ssvnc | Not affected | Not affected | Not affected | Vulnerable | Fixed |
tightvnc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
x11vnc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2018-7225
Medium prioritySome fixes available 29 of 41
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified...
4 affected packages
italc, libvncserver, tightvnc, vino
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
italc | Not in release | Not in release | Not in release | Fixed | Fixed |
libvncserver | Fixed | Fixed | Fixed | Fixed | Fixed |
tightvnc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vino | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2014-6053
Medium prioritySome fixes available 17 of 30
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a...
5 affected packages
italc, krfb, libvncserver, tightvnc, vino
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
italc | Not in release | Not in release | Not in release | Not affected | Fixed |
krfb | Not affected | Not affected | Not affected | Not affected | Not affected |
libvncserver | Not affected | Not affected | Not affected | Not affected | Not affected |
tightvnc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vino | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2009-0388
Medium priorityMultiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large...
1 affected package
tightvnc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
tightvnc | — | — | — | — | — |