An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
"extracted_events": [
{
"last_affected": "16.04"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "18.04"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "20.04"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "9.0"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "15.1"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "15.2"
}
],
"source": "CPE_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:libvncserver_project:libvncserver:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.9.13"
}
],
"source": [
"CPE_FIELD",
"REFERENCES"
]
}"2026-04-11T21:47:55Z"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"27286812576839115884543175160988269078",
"126378025424545499359211745975564175189",
"94072546939175517512903866765638939671",
"142913035614552476143277396473228735757",
"16491202129239839746453209863899231208",
"329118107097954020458462031759542038328",
"139540123818845539957203460069661562707",
"262702335076891001489415279451883678023",
"268278606668869684054629684412740624732",
"190302750283181718757184748493504315953"
]
},
"signature_type": "Line",
"id": "CVE-2020-14400-70f37e3b",
"signature_version": "v1",
"source": "https://github.com/libvnc/libvncserver/commit/53073c8d7e232151ea2ecd8a1243124121e10e2d",
"target": {
"file": "libvncserver/translate.c"
},
"deprecated": false
},
{
"digest": {
"length": 1002.0,
"function_hash": "53011332413877103642289004836945053853"
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2020-14400-bcfad6c4",
"source": "https://github.com/libvnc/libvncserver/commit/53073c8d7e232151ea2ecd8a1243124121e10e2d",
"target": {
"function": "rfbSetClientColourMapBGR233",
"file": "libvncserver/translate.c"
},
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-14400.json"