<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:13:40.885743+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:1811</id>
    <title>ALSA-2021:1811 — Moderate: libvncserver security update</title>
    <updated>2026-10-02T17:13:40.898726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libvncserver, AlmaLinux:8: libvncserver-devel</p>
<p>LibVNCServer is a C library that enables you to implement VNC server functionality into own programs.</p>
<p>Security Fix(es):</p>
<p>* libvncserver: uninitialized memory contents are vulnerable to Information Leak (CVE-2018-21247)</p>
<p>* libvncserver: buffer overflow in ConnectClientToUnixSock() (CVE-2019-20839)</p>
<p>* libvncserver: libvncserver/rfbregion.c has a NULL pointer dereference (CVE-2020-14397)</p>
<p>* libvncserver: libvncclient/rfbproto.c does not limit TextChat size (CVE-2020-14405)</p>
<p>* libvncserver: libvncserver/rfbserver.c has a divide by zero which could result in DoS (CVE-2020-25708)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:1811"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-03958</id>
    <title>bdu:2020-03958</title>
    <updated>2026-10-02T17:13:40.898802+00:00</updated>
    <content>bdu:2020-03958</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-03958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-949</id>
    <title>certfr-2021-avi-949 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T17:13:40.898822+00:00</updated>
    <content>certfr-2021-avi-949</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-36779</id>
    <title>cnvd-2020-36779</title>
    <updated>2026-10-02T17:13:40.898838+00:00</updated>
    <content>cnvd-2020-36779</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-36779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-70919</id>
    <title>EUVD-2026-70919</title>
    <updated>2026-10-02T17:13:40.898849+00:00</updated>
    <content>EUVD-2026-70919</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-70919"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-21247</id>
    <title>fkie_cve-2018-21247</title>
    <updated>2026-10-02T17:13:40.898859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-21247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-355f-mpqr-3mwv</id>
    <title>GHSA-355f-mpqr-3mwv</title>
    <updated>2026-10-02T17:13:40.898879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in LibVNCServer before 0.9.13. There is a memory leak in the libvncclient/rfbproto.c ConnectToRFBRepeater function.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-355f-mpqr-3mwv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-21247</id>
    <title>gsd-2018-21247</title>
    <updated>2026-10-02T17:13:40.898892+00:00</updated>
    <content>gsd-2018-21247</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-21247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-350-12</id>
    <title>ICSA-21-350-12 — Siemens SIMATIC ITC</title>
    <updated>2026-10-02T17:13:40.898902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow. LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution. LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function. LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a. A flaw was found in l…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-350-12"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0988-1</id>
    <title>openSUSE-SU-2020:0988-1 — Security update for LibVNCServer</title>
    <updated>2026-10-02T17:13:40.898946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for LibVNCServer</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0988-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:1922-1</id>
    <title>SUSE-SU-2020:1922-1 — Security update for LibVNCServer</title>
    <updated>2026-10-02T17:13:40.898965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for LibVNCServer</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:1922-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-21247</id>
    <title>UBUNTU-CVE-2018-21247</title>
    <updated>2026-10-02T17:13:40.898980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: x11vnc, Ubuntu:16.04:LTS: libvncserver, Ubuntu:Pro:16.04:LTS: x11vnc, Ubuntu:18.04:LTS: libvncserver, Ubuntu:Pro:18.04:LTS: x11vnc, Ubuntu:20.04:LTS: libvncserver, Ubuntu:20.04:LTS: veyon, Ubuntu:Pro:20.04:LTS: x11vnc, Ubuntu:22.04:LTS: veyon, Ubuntu:24.04:LTS: veyon and 2 more</p>
<p>An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-21247"/>
  </entry>
</feed>
