Libvnc Project / Libvncserver
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-50538 | libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write | HIGH | 8.8 | Aug 21, 2026 |
| CVE-2026-44988 | LibVNCClient Tight Gradient decoding allows malicious server-triggered heap/stack OOB writes | HIGH | 8.8 | May 27, 2026 |
| CVE-2026-32854 | LibVNCServer httpd proxy NULL Pointer Dereference | MEDIUM | 6.3 | Mar 24, 2026 |
| CVE-2026-32853 | LibVNCServer UltraZip Encoding Heap Out-of-bounds Read | MEDIUM | 6.9 | Mar 24, 2026 |
| CVE-2019-15690 | libvncserver: HandleCursorShape() integer overflow resulting in heap-based buffer overflow | CRITICAL | 9.8 | Jan 24, 2025 |
| CVE-2020-14396 | libvncserver: libvncclient/tls_openssl.c has a NULL pointer dereference | HIGH | 7.5 | Jun 17, 2020 |
| CVE-2020-14397 | libvncserver: libvncserver/rfbregion.c has a NULL pointer dereference | HIGH | 7.5 | Jun 17, 2020 |
| CVE-2020-14398 | libvncserver: an improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c | HIGH | 7.5 | Jun 17, 2020 |
| CVE-2020-14402 | libvncserver: libvncserver/corre.c allows out-of-bounds access via encodings | MEDIUM | 5.4 | Jun 17, 2020 |
| CVE-2020-14403 | libvncserver: libvncserver/hextile.c allows out-of-bounds access via encodings | MEDIUM | 5.4 | Jun 17, 2020 |
| CVE-2020-14404 | libvncserver: libvncserver/rre.c allows out-of-bounds access via encodings | MEDIUM | 5.4 | Jun 17, 2020 |
| CVE-2020-14405 | libvncserver: libvncclient/rfbproto.c does not limit TextChat size | MEDIUM | 6.5 | Jun 17, 2020 |
| CVE-2019-20839 | libvncserver: buffer overflow in ConnectClientToUnixSock() | HIGH | 7.5 | Jun 17, 2020 |
| CVE-2019-20840 | libvncserver: unaligned accesses in hybiReadAndDecode can lead to a crash | HIGH | 7.5 | Jun 17, 2020 |
| CVE-2018-21247 | libvncserver: uninitialized memory contents are vulnerable to Information Leak | HIGH | 7.5 | Jun 17, 2020 |
| CVE-2019-20788 | libvncserver: integer overflow and heap-based buffer overflow in libvncclient/cursor.c in HandleCursorShape function | CRITICAL | 9.8 | Apr 23, 2020 |
| CVE-2019-15681 | libvncserver: information disclosure and ASLR bypass | HIGH | 7.5 | Oct 29, 2019 |
| CVE-2018-20750 | libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (Incomplete fix for CVE-2018-15… | CRITICAL | 9.8 | Jan 30, 2019 |
| CVE-2018-20749 | libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (Incomplete fix for CVE-2018-15… | CRITICAL | 9.8 | Jan 30, 2019 |
| CVE-2018-20748 | libvncserver: Multiple heap out-of-bound writes in VNC client code (Incomplete fix for CVE-2018-20019) | CRITICAL | 9.8 | Jan 30, 2019 |
| CVE-2018-6307 | libvncserver: Use-after-free in file transfer extension server code allows for potential code execution | HIGH | 8.1 | Dec 19, 2018 |
| CVE-2018-20024 | libvncserver: NULL pointer dereference in VNC client code allows for denial of service | HIGH | 7.5 | Dec 19, 2018 |
| CVE-2018-20023 | libvncserver: Improper initialization in VNC Repeater client code allows for information disclosure | HIGH | 7.5 | Dec 19, 2018 |
| CVE-2018-20022 | libvncserver: Improper initialization in VNC client code allows for information disclosure | HIGH | 7.5 | Dec 19, 2018 |
| CVE-2018-20021 | libvncserver: Infinite loop in VNC client code allows for denial of service | HIGH | 7.5 | Dec 19, 2018 |
Showing 1 to 25 of 26 CVEs