{"id":"CVE-2014-0011","details":"Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.","modified":"2026-04-16T06:19:43.605839209Z","published":"2020-01-02T20:15:15Z","withdrawn":"2024-06-30T15:57:18.367628Z","related":["openSUSE-SU-2024:10056-1"],"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1050928"},{"type":"WEB","url":"https://github.com/TigerVNC/tigervnc/releases/tag/v1.3.1"}],"affected":[{"package":{"name":"vnc4","ecosystem":"Debian:10","purl":"pkg:deb/debian/vnc4?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1+X4.3.0+t-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2014-0011.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}