It was reported [1] that vncviewer could prompt for, and send, authentication credentials to a remote server without first properly validating the X.509 certificate. This could allow a malicious server to obtain a client's credentials because the client does not indicate to the user that a certificate is bad or missing.
A proposed patch [2] is being discussed.
[1] http://www.mail-archive.com/tigervnc-devel@lists.sourceforge.net/msg01342.html [2] http://www.mail-archive.com/tigervnc-devel@lists.sourceforge.net/msg01347.html