CVE-2026-107614
Description détaillée
An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.
Vecteur d'attaque (CVSS)
Dernières Vulnérabilités
CVE-2026-88647
A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.
CVE-2026-62167
Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-62166
Rejected reason: This CVE is a duplicate of another CVE.
