FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-18 11:12:36 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
cb3f036d-8c7f-11e6-924a-60a44ce6887blibvncserver -- multiple security vulnerabilities

Nicolas Ruff reports:

Integer overflow in MallocFrameBuffer() on client side.

Lack of malloc() return value checking on client side.

Server crash on a very large ClientCutText message.

Server crash when scaling factor is set to zero.

Multiple stack overflows in File Transfer feature.


Discovery 2014-09-23
Entry 2016-10-11
Modified 2016-10-18
libvncserver
< 0.9.10

http://seclists.org/oss-sec/2014/q3/639
CVE-2014-6051
CVE-2014-6052
CVE-2014-6053
CVE-2014-6054
CVE-2014-6055
ports/212380
64be967a-d379-11e6-a071-001e67f15f5alibvncserver -- multiple buffer overflows

libvnc server reports:

Two unrelated buffer overflows can be used by a malicious server to overwrite parts of the heap and crash the client (or possibly execute arbitrary code).


Discovery 2016-11-24
Entry 2017-01-09
libvncserver
< 0.9.11

https://github.com/LibVNC/libvncserver/pull/137
CVE-2016-9941
CVE-2016-9942
ports/215805