CRITICAL🇵🇱 Wersja polska

CVE-2019-8265

CVSS 9.8v3.0pub. 2019-03-08upd. 2024-11-21

UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1208.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Uvnc Ultravnc

    APP
    Uvnc
    < 1.2.2.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2026-7840CRITICAL9.3PL ✓same product

UltraVNC Repeater: global buffer overflow w serwerze HTTP (RCE bez uwierzytelnienia)

CVE-2026-7839CRITICAL9.1PL ✓same product

UltraVNC Repeater — hardcoded domyślne hasło administratora HTTP

CVE-2019-8271CRITICAL9.8PL ✓same product

UltraVNC: heap buffer overflow w obsłudze transferu plików (RCE)

CVE-2019-8266CRITICAL9.8PL ✓same product

UltraVNC: wielokrotny out-of-bounds access umożliwiający RCE w kliencie VNC

CVE-2019-8264CRITICAL9.8PL ✓same product

UltraVNC: podatność out-of-bounds w dekoderze Ultra2 klienta VNC (RCE)