Ultravnc is a remote-access and screen-sharing application with a narrow product portfolio centered on the main viewer and complementary tools such as its repeater and tabbed viewer components. The recurring vulnerability patterns in this vendor cluster around memory-buffer handling and access-control boundaries, characteristic of a native-code remote-display implementation, and the disclosures have an elevated tendency to acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultravnc over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1652HIGH Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malic | Apr 6, 2006 | 9.0 | 76 | NO | YES |
CVE-2008-0610HIGH Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, | Feb 6, 2008 | 9.3 | 67 | NO | YES |
CVE-2009-0388HIGH Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application cra | Feb 4, 2009 | 10.0 | 41 | NO | YES |
CVE-2016-5673HIGH UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in b | Aug 25, 2016 | 7.5 | 26 | NO | NO |
CVE-2008-5001HIGH Multiple stack-based buffer overflows in multiple functions in vncviewer/FileTransfer.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when | Nov 10, 2008 | 9.3 | 26 | NO | NO |
CVE-2006-2206HIGH The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing | May 5, 2006 | 10.0 | 25 | NO | NO |
CVE-2010-5248MEDIUM Untrusted search path vulnerability in UltraVNC 1.0.8.2 allows local users to gain privileges via a Trojan horse vnclang.dll file in the current working directory, as demonstrated | Sep 7, 2012 | 6.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultravnc.
Media articles that mention a CVE ID that affects a product developed by Ultravnc — matched by CVE ID, not by vendor name.