Lucene search

K
osvGoogleOSV:CVE-2017-18922
HistoryJun 30, 2020 - 11:15 a.m.

CVE-2017-18922

2020-06-3011:15:10
Google
osv.dev
2

6.5 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.7%

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

References