Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107613

MEDIUM NVD
CVSS Score 5.9
Severity MEDIUM
Published Oct 08, 2026
Vendor unknown

Description

A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), m_drvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition().

References