← volver
CVE-2019-15695CWE-121

CVE-2019-15695

3Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 4.5%
probabilidad de explotación
4.5%top 9% de las CVE
explotación observada
noninguna fuente lo reporta
TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability occurs due to insufficient sanitization of PixelFormat. Since remote attacker can choose offset from start of the buffer to start writing his values, exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.
Productos afectados
Kaspersky · TigerVNC