cbcvebase.

Debian Libvncserver vulnerabilities

45 known vulnerabilities affecting debian/libvncserver.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH20MEDIUM10LOW4

Vulnerabilities

Page 2 of 3
CVE-2018-20021P3HIGHCVSS 7.5fixed in libvncserver 0.9.11+dfsg-1.2 (bookworm)2018
CVE-2018-20021 [HIGH] CVE-2018-20021: libvncserver - LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835... LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM Scope: local bookworm: resolved (fixed in 0.9.11+dfsg-1.2) bullseye: resolved (fixed in 0.9.11+dfsg-1.2) forky: resolved (fixed in 0.9.11+dfsg-1.
debian
CVE-2018-20023P3HIGHCVSS 7.5fixed in libvncserver 0.9.11+dfsg-1.2 (bookworm)2018
CVE-2018-20023 [HIGH] CVE-2018-20023: libvncserver - LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Imprope... LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR Scope: local bookworm: resolved (fi
debian
CVE-2026-32853P3MEDIUMCVSS 6.9fixed in libvncserver 0.9.15+dfsg-3 (forky)2026
CVE-2026-32853 [MEDIUM] CVE-2026-32853: libvncserver - LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap ... LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause information disclosure or application crash. Attackers can exploit improper bounds checking in the HandleUltraZipBPP() function by manipulating subrectangle header counts
debian
CVE-2020-25708P3HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-25708 [HIGH] CVE-2020-25708: libvncserver - A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious cl... A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky
debian
CVE-2019-20839P3HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2019
CVE-2019-20839 [HIGH] CVE-2019-20839: libvncserver - libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a... libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.13+dfsg-1) trixie: resolved (fixed in 0.9.13+dfsg-1)
debian
CVE-2020-14400P3HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-14400 [HIGH] CVE-2020-14400: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is acce... An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9
debian
CVE-2020-14399P3HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-14399 [HIGH] CVE-2020-14399: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is acce... An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.
debian
CVE-2018-20024P3HIGHCVSS 7.5fixed in libvncserver 0.9.11+dfsg-1.2 (bookworm)2018
CVE-2018-20024 [HIGH] CVE-2018-20024: libvncserver - LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null poin... LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS. Scope: local bookworm: resolved (fixed in 0.9.11+dfsg-1.2) bullseye: resolved (fixed in 0.9.11+dfsg-1.2) forky: resolved (fixed in 0.9.11+dfsg-1.2) sid: resolved (fixed in 0.9.11+dfsg-1.2) trixie: resolved (fixed in 0.9.11+dfsg
debian
CVE-2020-14398P3HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-14398 [HIGH] CVE-2020-14398: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP ... An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.13+dfsg-1) trixie: resolved (fixed in 0.9.13+dfsg-1
debian
CVE-2019-15680P3LOWCVSS 7.5fixed in tightvnc 1:1.3.9-9.1 (bookworm)2019
CVE-2019-15680 [HIGH] CVE-2019-15680: libvncserver - TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP ... TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2019-20840P3HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2019
CVE-2019-20840 [HIGH] CVE-2019-20840: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c ... An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.13+dfsg-1) trixie: resolved (fixed in 0.9
debian
CVE-2014-6055P3MEDIUMCVSS 6.5fixed in libvncserver 0.9.9+dfsg-6.1 (bookworm)2014
CVE-2014-6055 [MEDIUM] CVE-2014-6055: libvncserver - Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.... Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message. Scope: local bookworm: resolved (f
debian
CVE-2020-14397P3HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-14397 [HIGH] CVE-2020-14397: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c ... An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.13+dfsg-1) trixie: resolved (fixed in 0.9.13+dfsg-1)
debian
CVE-2018-21247P3HIGHCVSS 7.5fixed in libvncserver 0.9.11+dfsg-1.2 (bookworm)2018
CVE-2018-21247 [HIGH] CVE-2018-21247: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. There is an information l... An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function. Scope: local bookworm: resolved (fixed in 0.9.11+dfsg-1.2) bullseye: resolved (fixed in 0.9.11+dfsg-1.2) forky: resolved (fixed in 0.9.11+dfsg-1.2) sid: resolved (fixed in 0.9.11+dfs
debian
CVE-2020-14396P3HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-14396 [HIGH] CVE-2020-14396: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.... An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.13+dfsg-1) trixie: resolved (fixed in 0.9.13+dfsg-1)
debian
CVE-2020-29260P4HIGHCVSS 7.5fixed in libvncserver 0.9.13+dfsg-5 (bookworm)2020
CVE-2020-29260 [HIGH] CVE-2020-29260: libvncserver - libvncclient v0.9.13 was discovered to contain a memory leak via the function rf... libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-5) bullseye: resolved (fixed in 0.9.13+dfsg-2+deb11u1) forky: resolved (fixed in 0.9.13+dfsg-5) sid: resolved (fixed in 0.9.13+dfsg-5) trixie: resolved (fixed in 0.9.13+dfsg-5)
debian
CVE-2020-14401P4MEDIUMCVSS 6.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-14401 [MEDIUM] CVE-2020-14401: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has ... An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.13+dfsg-1) trixie: resolved (fixed in 0.9.13+dfsg-1)
debian
CVE-2020-14405P4MEDIUMCVSS 6.5fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-14405 [MEDIUM] CVE-2020-14405: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c d... An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.13+dfsg-1) trixie: resolved (fixed in 0.9.13+dfsg-1)
debian
CVE-2014-6053P4MEDIUMCVSS 5.0fixed in libvncserver 0.9.9+dfsg-6.1 (bookworm)2014
CVE-2014-6053 [MEDIUM] CVE-2014-6053: libvncserver - The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNC... The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memory consumption or daemon crash) via a crafted message that is processed by using a single unchecked malloc. Scope:
debian
CVE-2020-14402P4MEDIUMCVSS 5.4fixed in libvncserver 0.9.13+dfsg-1 (bookworm)2020
CVE-2020-14402 [MEDIUM] CVE-2020-14402: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allo... An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings. Scope: local bookworm: resolved (fixed in 0.9.13+dfsg-1) bullseye: resolved (fixed in 0.9.13+dfsg-1) forky: resolved (fixed in 0.9.13+dfsg-1) sid: resolved (fixed in 0.9.13+dfsg-1) trixie: resolved (fixed in 0.9.13+dfsg-1)
debian
Debian Libvncserver vulnerabilities | cvebase