CVE-2019-15680 is a null pointer dereference vulnerability in TightVNC version 1.3.10, specifically within the HandleZlibBPP function. This flaw allows an unauthenticated attacker to cause a Denial of Service (DoS) by exploiting it over the network. With a CVSS score of 7.5 (HIGH), it presents a significant risk due to its low attack complexity and lack of user interaction required. While there is no known public exploit code or active exploitation, the vulnerability has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.10CPE matchmatch criteria | cpe:2.3:a:tightvnc:tightvnc:1.3.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.