Ultravnc

Vendor:

First CVE: Mar 5, 2019 · Active for 7 years

37
Total CVEs
More Total CVEs than 98% of tracked products
12.3
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ultravnc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2019
7 years ago
Most Recent CVE
Jul 1, 2026
27 days ago

CVE Severity & Scoring

Ultravnc37 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local4 (10.8%)
Network33 (89.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (89.2%)
High4 (10.8%)
Unknown0 (0.0%)
User Interaction
None34 (91.9%)
Unknown0 (0.0%)
Required3 (8.1%)
Privileges Required
Low4 (10.8%)
High1 (2.7%)
None32 (86.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/webgui/webu
Jul 1, 20269.844NONO
UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. In vncviewer/ClientConnection.cpp,
Jul 1, 20268.840NONO
UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is absent on f
Jul 1, 20269.138NONO
UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied name
Jul 1, 20267.634NONO
UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in result code execution. This attack a
Mar 8, 20199.833NONO
UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result in code execution. This attack
Mar 8, 20199.833NONO
UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAuth). In rfb/dh.cpp the Diffie-Hellman key exchange is perform
Jul 1, 20267.432NONO
UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In repeater/webgui/settings.c:225-272, after strncpy_s copies a
Jul 1, 20267.232NONO
UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. This attack appears to be exploit
Mar 8, 20199.832NONO
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This attack appears to be exploitable via network c
Mar 5, 20199.832NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Ultravnc

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.6.4.017.00.2%00