peter bassill · operator
$ cve CVE-2018-15127 JSON

CVE-2018-15127

9.8
CRITICAL · CVSS 3.0 · EPSS 15.1% (pctl 97)

Patch early

EPSS 15.1% — above the 10% action threshold.

Description

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS15.09% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2018-12-19
Last modified2026-06-17

Affected (9)

VendorProduct
canonicalubuntu linux
debiandebian linux
libvnc projectlibvncserver
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD