cbcvebase.

Uvnc Ultravnc vulnerabilities

37 known vulnerabilities affecting uvnc/ultravnc.

Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH14MEDIUM5LOW1

Vulnerabilities

Page 1 of 2
CVE-2026-7840P2CRITICALCVSS 9.8≤ 1.8.2.22026-07-01
CVE-2026-7840 [CRITICAL] CWE-787 CVE-2026-7840: UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administrat UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/webgui/webutils.c write the caller-supplied HTTP request URI into a fixed 1000-byte global buffer (hdrbuf) via unchecked sprintf calls. The HTTP receive buffer accepts URIs up to app
nvd
CVE-2026-7839P2CRITICALCVSS 9.1≤ 1.8.2.22026-07-01
CVE-2026-7839 [CRITICAL] CWE-798 CVE-2026-7839: UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded defaul UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is absent on first run the repeater writes the literal string "adminadmi2" as the admin password via strcpy_s(saved_password, 64, "adminadmi2"). The HTTP Basic-auth handler wi_decode_au
nvd
CVE-2026-7838P2HIGHCVSS 8.8≤ 1.8.2.22026-07-01
CVE-2026-7838 [HIGH] CWE-190 CVE-2026-7838: UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in th UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. In vncviewer/ClientConnection.cpp, the 4-byte network-supplied reasonLen field (type CARD32) is passed as reasonLen+1 to CheckBufferSize(). Because both operands are unsigned 32-bit, a reasonLen of 0xFFFFFFFF
nvd
CVE-2019-8275P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8275 [CRITICAL] CWE-170 CVE-2019-8275: UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, wh UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
nvd
CVE-2019-8268P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8268 [CRITICAL] CWE-193 CVE-2019-8268: UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with imp UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString function, which can potentially result code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1207.
nvd
CVE-2019-8272P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8272 [CRITICAL] CWE-193 CVE-2019-8272: UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potenti UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
nvd
CVE-2019-8273P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8273 [CRITICAL] CWE-122 CVE-2019-8273: UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file trans UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.
nvd
CVE-2019-8262P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-05
CVE-2019-8262 [CRITICAL] CWE-122 CVE-2019-8262: UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside U UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1204.
nvd
CVE-2018-15361P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-05
CVE-2018-15361 [CRITICAL] CWE-124 CVE-2018-15361: UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentiall UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
nvd
CVE-2019-8266P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8266 [CRITICAL] CWE-788 CVE-2019-8266: UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usa UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of ClientConnection::Copybuffer function in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. User interaction is required to trigger these vulnerabilities. These vulner
nvd
CVE-2019-8274P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8274 [CRITICAL] CWE-122 CVE-2019-8274: UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file trans UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in result code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.
nvd
CVE-2019-8271P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8271 [CRITICAL] CWE-122 CVE-2019-8271: UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file trans UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which can potentially result code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.
nvd
CVE-2019-8280P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8280 [CRITICAL] CWE-788 CVE-2019-8280: UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, whic UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially result code execution. This attack appear to be exploitable via network connectivity. This vulnerability has been fixed in revision 1204.
nvd
CVE-2019-8258P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-05
CVE-2019-8258 [CRITICAL] CWE-122 CVE-2019-8258: UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results cod UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
nvd
CVE-2019-8265P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8265 [CRITICAL] CWE-788 CVE-2019-8265: UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usa UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1208.
nvd
CVE-2019-8264P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-08
CVE-2019-8264 [CRITICAL] CWE-788 CVE-2019-8264: UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, w UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1204.
nvd
CVE-2026-7829P3HIGHCVSS 7.2≤ 1.8.2.22026-07-01
CVE-2026-7829 [HIGH] CWE-787 CVE-2026-7829: UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/de UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In repeater/webgui/settings.c:225-272, after strncpy_s copies a rule token into temp1[rule1] (25-byte destination) or temp2/temp3 (16-byte destination), the code unconditionally writes a NUL terminator at temp1[rule1][len] = 0 without clam
nvd
CVE-2019-8260P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-05
CVE-2019-8260 [CRITICAL] CWE-125 CVE-2019-8260: UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.
nvd
CVE-2019-8261P3CRITICALCVSS 9.8fixed in 1.2.2.32019-03-05
CVE-2019-8261 [CRITICAL] CWE-125 CVE-2019-8261: UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decode UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.
nvd
CVE-2026-7831P3HIGHCVSS 7.6≤ 1.8.2.22026-07-01
CVE-2026-7831 [HIGH] CWE-193 CVE-2026-7831: UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit m UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls ReadString(_dn, 2024). ReadString writes the NUL terminator at buf[length], i.e., _dn
nvd
Uvnc Ultravnc vulnerabilities | cvebase