Gnome Gtk-Vnc vulnerabilities
3 known vulnerabilities affecting gnome/gtk-vnc.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1
Vulnerabilities
Page 1 of 1
CVE-2017-5885P3CRITICALCVSS 9.8≤ 0.6.02017-02-28
CVE-2017-5885 [CRITICAL] CWE-190 CVE-2017-5885: Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functi
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
nvdosv
CVE-2017-1000044P3CRITICALCVSS 9.8v0.4.22017-07-17
CVE-2017-1000044 [CRITICAL] CWE-119 CVE-2017-1000044: gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer whi
gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering
nvdosv
CVE-2017-5884P3HIGHCVSS 7.8≤ 0.6.02017-02-28
CVE-2017-5884 [HIGH] CWE-118 CVE-2017-5884: gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allo
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
nvdosv