Vulnerabilidades en uvnc
14 resultadosAnálisis Vexday
UltraVNC apresenta 10 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e ativa do produto. Duas dessas falhas atingem nível crítico, predominantemente associadas a estouro de buffer (CWE-787), porém nenhuma está sob exploração confirmada em ataques documentados no momento.
CVE-2026-7840CRITICALUltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)EPSS 2.6%CVE-2026-7838HIGHUltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason lengthEPSS 1.9%CVE-2026-7828MEDIUMUltraVNC repeater integer overflow in win_log malloc leading to heap overflowEPSS 1.4%CVE-2026-7829HIGHUltraVNC repeater authenticated out-of-bounds write in rule parser via oversized tokenEPSS 0.9%CVE-2026-7831HIGHUltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsingEPSS 0.7%CVE-2019-25600HIGHUltraVNC Viewer 1.2.2.4 Denial of Service via Buffer OverflowEPSS 0.7%CVE-2026-7839CRITICALUltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin accessEPSS 0.7%CVE-2026-44042LOWUltraVNC repeater wi_uudecode off-by-one in base64 decode boundary checkEPSS 0.5%CVE-2019-25564MEDIUMPCHelpWareV2 1.0.0.5 Denial of Service via Group FieldEPSS 0.4%CVE-2026-44041MEDIUMUltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminatedEPSS 0.4%CVE-2026-44040MEDIUMUltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge bytesEPSS 0.4%CVE-2026-7830HIGHUltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interceptionEPSS 0.3%CVE-2019-25601MEDIUMUltraVNC Launcher 1.2.2.4 Denial of Service Buffer OverflowEPSS 0.3%CVE-2019-25563MEDIUMPCHelpWareV2 1.0.0.5 Denial of Service via SC CreationEPSS 0.2%