Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tigervnc CRITICAL 9.8
CVE-2026-34352

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, b…

Fix: 1.16.2+
Fix from $2,300 2026-03-26
Tigervnc CRITICAL 9.8
CVE-2014-0011

Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow r…

Fix: 1.3.1+
Fix from $2,300 2020-01-02
Tigervnc HIGH 7.2
CVE-2019-15695

TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability …

Fix: 1.10.1+
Fix from $1,950 2019-12-26
Tigervnc HIGH 7.2
CVE-2019-15691

TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If deco…

Fix: 1.10.1+
Fix from $1,950 2019-12-26
Tigervnc HIGH 7.2
CVE-2019-15692

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value …

Fix: 1.10.1+
Fix from $1,950 2019-12-26
Tigervnc HIGH 7.2
CVE-2019-15693

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerabil…

Fix: 1.10.1+
Fix from $1,950 2019-12-26
Tigervnc HIGH 7.2
CVE-2019-15694

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs…

Fix: 1.10.1+
Fix from $1,950 2019-12-26
Tigervnc HIGH 8.8
CVE-2017-7393

In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or po…

Patch available
Fix from $1,950 2017-04-01
Tigervnc HIGH 7.5
CVE-2017-7392

In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.

Patch available
Fix from $1,950 2017-04-01
Tigervnc HIGH 7.5
CVE-2017-7394

In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.

Patch available
Fix from $1,950 2017-04-01
Tigervnc HIGH 7.5
CVE-2017-7396

In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.

Patch available
Fix from $1,950 2017-04-01
Tigervnc MEDIUM 6.5
CVE-2017-7395

In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.

Patch available
Fix from $1,600 2017-04-01
Tigervnc CRITICAL 9.8
CVE-2017-5581

Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE m…

Fix: after 1.7
Fix from $2,300 2017-02-28
Tigervnc HIGH 7.5
CVE-2014-8240

Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related t…

Mitigation only
Fix from $1,950 2014-10-16
Tigervnc MEDIUM 5.8
CVE-2011-1775

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the ser…

Mitigation only
Fix from $1,600 2011-05-26