Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rx9w-c6jv-2grg

Опубликовано: 24 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

EPSS

Процентиль: 50%
0.00733
Низкий

8.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 9.8
redhat
больше 6 лет назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 8.8
nvd
больше 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 8.8
debian
больше 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow ...

oracle-oval
больше 6 лет назад

ELSA-2020-0920: libvncserver security update (IMPORTANT)

EPSS

Процентиль: 50%
0.00733
Низкий

8.8 High

CVSS3

Дефекты

CWE-122