Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libvnc Project

First CVE: Dec 19, 2018Active for: 8 yearsTotal CVEs: 27
56.6
VTI Score
TOP TARGET

The Libvnc Project maintains a widely embedded remote-access library that, despite a narrow product footprint centered on Libvncserver, sits deep in the software supply chain of VNC implementations across servers, desktops, and thin clients. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and protocol-parsing complexity of a C-based RFB (Remote Framebuffer) implementation that runs with elevated privilege in many deployments. The recurring weakness classes—including out-of-bounds writes, improper initialization, NULL pointer dereferences, infinite loops, and use-after-free conditions—are characteristic of native code handling untrusted network input, and a single flaw can propagate to every downstream VNC application that embeds the library. Defenders should inventory VNC servers and clients in their environment and treat Libvnc advisories as high-priority, particularly for internet-facing or privileged remote-access sessions, since remediation typically depends on downstream vendors rebuilding and redistributing their applications. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
5.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libvnc Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2018
7 years ago
Most Recent CVE
Mar 24, 2026
122 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-6307HIGH
LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execu
Dec 19, 20188.139NONO
CVE-2018-15127CRITICAL
LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code e
Dec 19, 20189.838NONO
CVE-2018-20019CRITICAL
LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution
Dec 19, 20189.835NONO
CVE-2018-15126CRITICAL
LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execu
Dec 19, 20189.835NONO
CVE-2018-20020CRITICAL
LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code executi
Dec 19, 20189.834NONO
CVE-2018-20750CRITICAL
LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
Jan 30, 20199.833NONO
CVE-2019-20788CRITICAL
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overl
Apr 23, 20209.832NONO
CVE-2018-20749CRITICAL
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
Jan 30, 20199.832NONO
CVE-2018-20748CRITICAL
LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.
Jan 30, 20199.831NONO
CVE-2026-32854HIGH
LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c th
Mar 24, 20267.529NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
15%
56%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None25 (92.6%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low4 (14.8%)
High0 (0.0%)
None23 (85.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libvnc Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libvnc Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libvnc Project's Products

View all 3 CNAs →

Top CWEs