Tarantella specializes in secure remote-access and desktop-virtualization software, with its vulnerability profile concentrated in flagship products such as Tarantella Enterprise and Secure Global Desktop. The vendor's disclosures recur around memory-safety and pointer-handling weakness classes including NULL-pointer dereferences and out-of-bounds reads, reflecting the parsing and state-management demands of its client-server architecture, and have a consistent tendency to acquire public exploit code. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tarantella over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0079HIGH The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t | Nov 23, 2004 | 7.5 | 29 | NO | NO |
CVE-2002-0211MEDIUM Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow | May 16, 2002 | 6.2 | 26 | NO | YES |
CVE-2001-0805MEDIUM Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the pg parameter. | Dec 6, 2001 | 5.0 | 25 | NO | YES |
CVE-2004-0112MEDIUM The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi | Nov 23, 2004 | 5.0 | 23 | NO | NO |
CVE-2002-0203MEDIUM ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg par | May 16, 2002 | 5.0 | 19 | NO | NO |
CVE-2004-0081MEDIUM OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Co | Nov 23, 2004 | 5.0 | 18 | NO | NO |
CVE-2005-0486MEDIUM Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reve | Mar 30, 2005 | 5.0 | 15 | NO | NO |
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file. | May 31, 2002 | 1.2 | 15 | NO | YES |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tarantella.
Media articles that mention a CVE ID that affects a product developed by Tarantella — matched by CVE ID, not by vendor name.