CVE-2016-10207: Opensuse Leap

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.

Affected products

  • Opensuse Leap: version 42.1 only; version 42.2 only
  • Tigervnc Tigervnc: version 0.0.90 only; version 0.0.91 only; version 1.0 only; version 1.0.1 only; version 1.1.0 only; version 1.3 only; …

Published 2017-02-28. Last modified 2026-06-17.