<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:01:54 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:3385 — Important: libvncserver security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:3385</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libvncserver-devel&lt;/p&gt;
&lt;p&gt;LibVNCServer is a C library that enables you to implement VNC server functionality into own programs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvncserver: websocket decoding buffer overflow (CVE-2017-18922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libvncserver-devel&lt;/p&gt;
&lt;p&gt;LibVNCServer is a C library that enables you to implement VNC server functionality into own programs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvncserver: websocket decoding buffer overflow (CVE-2017-18922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:3385</guid>
    </item>
    <item>
      <title>bdu:2020-03957</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-03957</link>
      <description>bdu:2020-03957</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-03957</guid>
    </item>
    <item>
      <title>certfr-2021-avi-949 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-949</link>
      <description>certfr-2021-avi-949</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-949</guid>
    </item>
    <item>
      <title>cnvd-2020-36778</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-36778</link>
      <description>cnvd-2020-36778</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-36778</guid>
    </item>
    <item>
      <title>EUVD-2026-80667</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-80667</link>
      <description>EUVD-2026-80667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-80667</guid>
    </item>
    <item>
      <title>fkie_cve-2017-18922</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-18922</link>
      <description>&lt;p&gt;It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-18922</guid>
    </item>
    <item>
      <title>GHSA-hq8f-cpqj-qph2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hq8f-cpqj-qph2</link>
      <description>&lt;p&gt;It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hq8f-cpqj-qph2</guid>
    </item>
    <item>
      <title>gsd-2017-18922</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-18922</link>
      <description>gsd-2017-18922</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-18922</guid>
    </item>
    <item>
      <title>ICSA-21-350-12 — Siemens SIMATIC ITC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-350-12</link>
      <description>&lt;p&gt;websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow. LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution. LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function. LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a. A flaw was found in l…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow. LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution. LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function. LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a. A flaw was found in l…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-350-12</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0960-1 — Security update for LibVNCServer</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0960-1</link>
      <description>&lt;p&gt;Security update for LibVNCServer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for LibVNCServer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0960-1</guid>
    </item>
    <item>
      <title>RHSA-2020:3456 — Red Hat Security Advisory: libvncserver security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3456</link>
      <description>&lt;p&gt;libvncserver: websocket decoding buffer overflow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libvncserver: websocket decoding buffer overflow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3456</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:1873-1 — Security update for LibVNCServer</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:1873-1</link>
      <description>&lt;p&gt;Security update for LibVNCServer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for LibVNCServer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:1873-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-18922</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-18922</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: x11vnc, Ubuntu:16.04:LTS: libvncserver, Ubuntu:18.04:LTS: libvncserver, Ubuntu:20.04:LTS: libvncserver, Ubuntu:20.04:LTS: veyon, Ubuntu:22.04:LTS: veyon, Ubuntu:24.04:LTS: veyon, Ubuntu:25.10: veyon, Ubuntu:26.04:LTS: veyon&lt;/p&gt;
&lt;p&gt;It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: x11vnc, Ubuntu:16.04:LTS: libvncserver, Ubuntu:18.04:LTS: libvncserver, Ubuntu:20.04:LTS: libvncserver, Ubuntu:20.04:LTS: veyon, Ubuntu:22.04:LTS: veyon, Ubuntu:24.04:LTS: veyon, Ubuntu:25.10: veyon, Ubuntu:26.04:LTS: veyon&lt;/p&gt;
&lt;p&gt;It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-18922</guid>
    </item>
  </channel>
</rss>
