In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7394