Libvncserver

Libvncserver

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 36.87%
  • Veröffentlicht 15.12.2014 18:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memor...

Exploit
  • EPSS 5.24%
  • Veröffentlicht 15.12.2014 18:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitra...

  • EPSS 40.57%
  • Veröffentlicht 06.10.2014 14:55:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) Palm...

  • EPSS 6.61%
  • Veröffentlicht 30.09.2014 16:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which...

  • EPSS 11.16%
  • Veröffentlicht 30.09.2014 16:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) d...

  • EPSS 3.22%
  • Veröffentlicht 18.07.2006 15:40:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, a different issue ...