CVE Tools

Libvncserver-project

6 CVEs tracked since 2016. Since Dec 2016, none of them reached CISA KEV.

Libvncserver-project CVEs per month

Dec 2016 to Jun 2020. Point at a month, or focus the strip and use the arrow keys.
Libvncserver-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2016-1220
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0640

Products

The products that kept showing up in Libvncserver-project's monthly top three, with their CVEs summed over those months.

  1. Libvncserver62 months

Latest CVEs

The 12 most recently published vulnerabilities affecting Libvncserver-project.

  1. CVE-2026-32854LibVNCServer httpd proxy NULL Pointer Dereference7.5
  2. CVE-2026-32853LibVNCServer UltraZip Encoding Heap Out-of-bounds Read8.1
  3. CVE-2020-29260libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().7.5
  4. CVE-2020-25708A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a ...7.5
  5. CVE-2017-18922It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket ...9.8
  6. CVE-2020-14399An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.7.5
  7. CVE-2020-14400An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerab...7.5
  8. CVE-2020-14401An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.6.5
  9. CVE-2010-5304A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a spec...7.5
  10. CVE-2018-7225An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive...9.8
  11. CVE-2016-9942Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a c...9.8
  12. CVE-2016-9941Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via ...9.8

The record

Peak rank
#53 in Dec 2016
Busiest month shown
Jun 2020, 4 CVEs
Months with a KEV entry
0 since Dec 2016
Monthly snapshots
2 since 2016
Libvncserver-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store