<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Disclosure on Bas Levering</title>
    <link>https://baslevering.com/tags/disclosure/</link>
    <description>Recent content in Disclosure on Bas Levering</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 29 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://baslevering.com/tags/disclosure/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A pre-auth heap overflow in libvncclient&#39;s Tight decoder</title>
      <link>https://baslevering.com/posts/libvncclient-tight-oob-write/</link>
      <pubDate>Fri, 29 May 2026 00:00:00 +0000</pubDate>
      <guid>https://baslevering.com/posts/libvncclient-tight-oob-write/</guid>
      <description>GHSA-v9pm-47h4-jcq8 — a malicious VNC server can crash or take over any client built on libvncclient, default build, no auth. My first CVE, and why the client trusting the server is the whole problem.</description>
    </item>
  </channel>
</rss>
