Search CVE reports
1 – 10 of 15 results
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | — | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that...
9 affected packages
xorg-server-lts-wily, xorg-server-lts-xenial, xwayland, xorg-server, xorg-server-hwe-16.04...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| xorg-server-lts-wily | — | — | Not in release | Not in release | Not in release |
| xorg-server-lts-xenial | — | — | Not in release | Not in release | Not in release |
| xwayland | Fixed | Fixed | Fixed | Not in release | Not in release |
| xorg-server | Fixed | Fixed | Fixed | Fixed | Fixed |
| xorg-server-hwe-16.04 | — | — | Not in release | Not in release | Not in release |
| xorg-server-hwe-18.04 | — | — | Not in release | Not in release | Fixed |
| xorg-server-lts-utopic | — | — | Not in release | Not in release | Not in release |
| xorg-server-lts-vivid | — | — | Not in release | Not in release | Not in release |
| tigervnc | Not affected | Not affected | Fixed | Fixed | Ignored |
Some fixes available 1 of 3
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any...
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | — | Not affected | Not affected | Fixed | Needs evaluation |
TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability occurs due to insufficient sanitization of PixelFormat. Since remote attacker can...
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | — | Not affected | Not affected | Not affected | Needs evaluation |
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing MemOutStream. Exploitation of this...
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | Not affected | Not affected | Not affected | Not affected | Ignored |
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be...
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | — | Not affected | Not affected | Not affected | Needs evaluation |
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value checks. Exploitation of this vulnerability could potentially result into remote...
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | — | Not affected | Not affected | Not affected | Needs evaluation |
TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access stack...
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | Not affected | Not affected | Not affected | Not affected | Ignored |
In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | — | — | — | — | Not affected |
In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.
1 affected package
tigervnc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tigervnc | — | — | — | — | Not affected |