Tigervnc
30 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Tigervnc, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Tigervnc CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 8 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 30 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High24
- Medium3
Latest CVEs
The 15 most recently published vulnerabilities affecting Tigervnc.
- CVE-2026-34352In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.8.5
- CVE-2025-26601Xorg: xwayland: use-after-free in syncinittrigger()7.8
- CVE-2025-26600Xorg: xwayland: use-after-free in playreleasedevents()7.8
- CVE-2025-26599Xorg: xwayland: use of uninitialized pointer in compredirectwindow()7.8
- CVE-2025-26598Xorg: xwayland: out-of-bounds write in createpointerbarrierclient()7.8
- CVE-2025-26597Xorg: xwayland: buffer overflow in xkbchangetypesofkey()7.8
- CVE-2025-26596Xorg: xwayland: heap overflow in xkbwritekeysyms()7.8
- CVE-2025-26595Xorg: xwayland: buffer overflow in xkbvmodmasktext()7.8
- CVE-2025-26594X.org: xwayland: use-after-free of the root cursor7.8
- CVE-2024-0409Xorg-x11-server: selinux context corruption7.8
- CVE-2024-0408Xorg-x11-server: selinux unlabeled glx pbuffer5.5
- CVE-2023-6478Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty7.6
- CVE-2023-6377Xorg-x11-server: out-of-bounds memory reads/writes in xkb button actions7.8
- CVE-2020-26117In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a ce...8.1
- CVE-2014-0011Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (...9.8
Product grouping is registry-driven, with AI assist and human review. How it works