7.5

CVE-2020-14397

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.

Data is provided by the National Vulnerability Database (NVD)
Libvnc ProjectLibvncserver Version <= 0.9.12
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version18.10
CanonicalUbuntu Linux Version20.04 SwEditionlts
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
SiemensSimatic Itc1500 Firmware Version >= 3.0.0.0 < 3.2.1.0
   SiemensSimatic Itc1500 Version-
SiemensSimatic Itc1500 Pro Firmware Version >= 3.0.0.0 < 3.2.1.0
   SiemensSimatic Itc1500 Pro Version-
SiemensSimatic Itc1900 Firmware Version >= 3.0.0.0 < 3.2.1.0
   SiemensSimatic Itc1900 Version-
SiemensSimatic Itc1900 Pro Firmware Version >= 3.0.0.0 < 3.2.1.0
   SiemensSimatic Itc1900 Pro Version-
SiemensSimatic Itc2200 Firmware Version >= 3.0.0.0 < 3.2.1.0
   SiemensSimatic Itc2200 Version-
SiemensSimatic Itc2200 Pro Firmware Version >= 3.0.0.0 < 3.2.1.0
   SiemensSimatic Itc2200 Pro Version-
OpensuseLeap Version15.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.44% 0.886
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.