Skip to main content

Vendor archive

ultravnc CVEs

Beta · best-effort

7 CVEs tagged to vendor ultravnc5 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2016-5673

Published Aug 25, 2016

UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5248

Published Sep 7, 2012

Untrusted search path vulnerability in UltraVNC 1.0.8.2 allows local users to gain privileges via a Trojan horse vnclang.dll file in the current working directory, as demonstrated…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0388

Published Feb 4, 2009

Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application cr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5001

Published Nov 10, 2008

Multiple stack-based buffer overflows in multiple functions in vncviewer/FileTransfer.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0610

Published Feb 6, 2008

Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-2206

Published May 5, 2006

The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-1652

Published Apr 6, 2006

Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a mali…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1