LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20749.json"