← Back

Libvncserver

libvncserver

Vendor: Libvncserver • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianLibvncserver
3Debian Linux
LibvncserverUbuntu Linux
May 6, 2026
Dec 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to ca...Show more
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memory consumption or daemon crash) via a crafted message that is processed by using a single unchecked malloc.Show less
4Canonical
DebianLibvncserver+1 more
4Debian Linux
LibvncserverSolaris+1 more
May 6, 2026
Dec 15, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application cras...Show more
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVNCReSizeFrameBuffer message.Show less
3Canonical
DebianLibvncserver
3Debian Linux
LibvncserverUbuntu Linux
May 6, 2026
Oct 6, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in th...Show more
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.Show less
4Debian
FedoraprojectLibvncserver+1 more
5Debian Linux
Enterprise Linux Server AusEnterprise Linux Server Eus+2 more
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary cod...Show more
Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.Show less
5Debian
FedoraprojectLibvncserver+2 more
6Debian Linux
Enterprise Linux Server AusEnterprise Linux Server Eus+3 more
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement...Show more
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.Show less
1Libvncserver
1Libvncserver
Apr 16, 2026
Jul 18, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by...Show more
auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, a different issue than CVE-2006-2369.Show less