CVE-2014-0011
CRITICAL9.8EPSS 0.51%發布日:2020/1/2修改日:2026/4/16
也稱為:openSUSE-SU-2024:10056-1
描述
Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.
受影響套件(1)
- Debian/vnc4from 0, < 4.1.1+X4.3.0+t-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |