rpm package
suse/LibVNCServer&distro=SUSE Linux Enterprise Point of Sale 11 SP3
pkg:rpm/suse/LibVNCServer&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3
Vulnerabilities (21)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-15690 | Hig | 8.8 | < 0.9.1-160.14.1 | 0.9.1-160.14.1 | Jan 24, 2025 | LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution. | |
| CVE-2020-25708 | — | < 0.9.1-160.22.1 | 0.9.1-160.22.1 | Nov 27, 2020 | A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service. | ||
| CVE-2020-14397 | — | < 0.9.1-160.19.1 | 0.9.1-160.19.1 | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference. | ||
| CVE-2020-14398 | — | < 0.9.1-160.19.1 | 0.9.1-160.19.1 | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c. | ||
| CVE-2020-14399 | — | < 0.9.1-160.19.1 | 0.9.1-160.19.1 | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed. | ||
| CVE-2020-14400 | — | < 0.9.1-160.19.1 | 0.9.1-160.19.1 | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary | ||
| CVE-2020-14401 | — | < 0.9.1-160.19.1 | 0.9.1-160.19.1 | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow. | ||
| CVE-2020-14402 | — | < 0.9.1-160.19.1 | 0.9.1-160.19.1 | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings. | ||
| CVE-2019-20788 | — | < 0.9.1-160.14.1 | 0.9.1-160.14.1 | Apr 23, 2020 | libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690. | ||
| CVE-2019-15681 | — | < 0.9.1-160.14.1 | 0.9.1-160.14.1 | Oct 29, 2019 | LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory a | ||
| CVE-2018-20750 | — | < 0.9.1-160.9.1 | 0.9.1-160.9.1 | Jan 30, 2019 | LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. | ||
| CVE-2018-20749 | — | < 0.9.1-160.9.1 | 0.9.1-160.9.1 | Jan 30, 2019 | LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. | ||
| CVE-2018-20748 | — | < 0.9.1-160.9.1 | 0.9.1-160.9.1 | Jan 30, 2019 | LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. | ||
| CVE-2018-6307 | — | < 0.9.1-160.6.1 | 0.9.1-160.6.1 | Dec 19, 2018 | LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution. | ||
| CVE-2018-20024 | — | < 0.9.1-160.6.1 | 0.9.1-160.6.1 | Dec 19, 2018 | LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS. | ||
| CVE-2018-20022 | — | < 0.9.1-160.6.1 | 0.9.1-160.6.1 | Dec 19, 2018 | LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can | ||
| CVE-2018-20021 | — | < 0.9.1-160.6.1 | 0.9.1-160.6.1 | Dec 19, 2018 | LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM | ||
| CVE-2018-20020 | — | < 0.9.1-160.6.1 | 0.9.1-160.6.1 | Dec 19, 2018 | LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution | ||
| CVE-2018-20019 | — | < 0.9.1-160.6.1 | 0.9.1-160.6.1 | Dec 19, 2018 | LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution | ||
| CVE-2018-15127 | — | < 0.9.1-160.6.1 | 0.9.1-160.6.1 | Dec 19, 2018 | LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution |
- affected < 0.9.1-160.14.1fixed 0.9.1-160.14.1
LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.
- CVE-2020-25708Nov 27, 2020affected < 0.9.1-160.22.1fixed 0.9.1-160.22.1
A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.
- CVE-2020-14397Jun 17, 2020affected < 0.9.1-160.19.1fixed 0.9.1-160.19.1
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.
- CVE-2020-14398Jun 17, 2020affected < 0.9.1-160.19.1fixed 0.9.1-160.19.1
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
- CVE-2020-14399Jun 17, 2020affected < 0.9.1-160.19.1fixed 0.9.1-160.19.1
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.
- CVE-2020-14400Jun 17, 2020affected < 0.9.1-160.19.1fixed 0.9.1-160.19.1
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
- CVE-2020-14401Jun 17, 2020affected < 0.9.1-160.19.1fixed 0.9.1-160.19.1
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
- CVE-2020-14402Jun 17, 2020affected < 0.9.1-160.19.1fixed 0.9.1-160.19.1
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
- CVE-2019-20788Apr 23, 2020affected < 0.9.1-160.14.1fixed 0.9.1-160.14.1
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
- CVE-2019-15681Oct 29, 2019affected < 0.9.1-160.14.1fixed 0.9.1-160.14.1
LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory a
- CVE-2018-20750Jan 30, 2019affected < 0.9.1-160.9.1fixed 0.9.1-160.9.1
LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
- CVE-2018-20749Jan 30, 2019affected < 0.9.1-160.9.1fixed 0.9.1-160.9.1
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
- CVE-2018-20748Jan 30, 2019affected < 0.9.1-160.9.1fixed 0.9.1-160.9.1
LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.
- CVE-2018-6307Dec 19, 2018affected < 0.9.1-160.6.1fixed 0.9.1-160.6.1
LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution.
- CVE-2018-20024Dec 19, 2018affected < 0.9.1-160.6.1fixed 0.9.1-160.6.1
LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.
- CVE-2018-20022Dec 19, 2018affected < 0.9.1-160.6.1fixed 0.9.1-160.6.1
LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can
- CVE-2018-20021Dec 19, 2018affected < 0.9.1-160.6.1fixed 0.9.1-160.6.1
LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
- CVE-2018-20020Dec 19, 2018affected < 0.9.1-160.6.1fixed 0.9.1-160.6.1
LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution
- CVE-2018-20019Dec 19, 2018affected < 0.9.1-160.6.1fixed 0.9.1-160.6.1
LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution
- CVE-2018-15127Dec 19, 2018affected < 0.9.1-160.6.1fixed 0.9.1-160.6.1
LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
Page 1 of 2