CVE-2006-1652 describes multiple buffer overflow vulnerabilities in UltraVNC 1.0.1 and earlier, as well as tabbed_viewer 1.29. These flaws allow for user-assisted remote code execution on clients via a malicious server sending a long string to TCP port 5900, and denial of service on servers through a long HTTP GET request to TCP port 5800. With a CVSS score of 9.0, this vulnerability is critical, enabling complete compromise of confidentiality, integrity, and availability with low attack complexity. While not on the CISA KEV catalog, exploit modules are publicly available in Metasploit and ExploitDB, indicating a high potential for exploitation despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.29CPE matchmatch criteria | cpe:2.3:a:ultravnc:tabbed_viewer:1.29:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:ultravnc:vnc_viewer:1.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.