Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rx9w-c6jv-2grg

Опубликовано: 24 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

EPSS

Процентиль: 82%
0.01662
Низкий

8.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 9.8
redhat
около 6 лет назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 8.8
nvd
около 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 8.8
debian
около 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow ...

oracle-oval
почти 6 лет назад

ELSA-2020-0920: libvncserver security update (IMPORTANT)

EPSS

Процентиль: 82%
0.01662
Низкий

8.8 High

CVSS3

Дефекты

CWE-122