The Libvnc Project maintains a widely embedded remote-access library that, despite a narrow product footprint centered on Libvncserver, sits deep in the software supply chain of VNC implementations across servers, desktops, and thin clients. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and protocol-parsing complexity of a C-based RFB (Remote Framebuffer) implementation that runs with elevated privilege in many deployments. The recurring weakness classes—including out-of-bounds writes, improper initialization, NULL pointer dereferences, infinite loops, and use-after-free conditions—are characteristic of native code handling untrusted network input, and a single flaw can propagate to every downstream VNC application that embeds the library. Defenders should inventory VNC servers and clients in their environment and treat Libvnc advisories as high-priority, particularly for internet-facing or privileged remote-access sessions, since remediation typically depends on downstream vendors rebuilding and redistributing their applications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libvnc Project over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6307HIGH LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execu | Dec 19, 2018 | 8.1 | 39 | NO | NO |
CVE-2018-15127CRITICAL LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code e | Dec 19, 2018 | 9.8 | 38 | NO | NO |
CVE-2018-20019CRITICAL LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution | Dec 19, 2018 | 9.8 | 35 | NO | NO |
CVE-2018-15126CRITICAL LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execu | Dec 19, 2018 | 9.8 | 35 | NO | NO |
CVE-2018-20020CRITICAL LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code executi | Dec 19, 2018 | 9.8 | 34 | NO | NO |
CVE-2018-20750CRITICAL LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. | Jan 30, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-20788CRITICAL libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overl | Apr 23, 2020 | 9.8 | 32 | NO | NO |
CVE-2018-20749CRITICAL LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. | Jan 30, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-20748CRITICAL LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. | Jan 30, 2019 | 9.8 | 31 | NO | NO |
CVE-2026-32854HIGH LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c th | Mar 24, 2026 | 7.5 | 29 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libvnc Project.
Media articles that mention a CVE ID that affects a product developed by Libvnc Project — matched by CVE ID, not by vendor name.