Vulnerabilidades em Uvnc
14 resultadosAnálise Vexday
UltraVNC apresenta um portfólio reduzido de 4 vulnerabilidades documentadas, nenhuma atualmente sob exploração ativa conhecida (KEV). A fraqueza dominante é buffer overflow (CWE-787), típica de software legado em C/C++, sem registros de divulgação recente que ampliem o risco imediato.
CVE-2026-7840CRITICALUltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)EPSS 2.6%CVE-2026-7838HIGHUltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason lengthEPSS 1.9%CVE-2026-7828MEDIUMUltraVNC repeater integer overflow in win_log malloc leading to heap overflowEPSS 1.4%CVE-2026-7829HIGHUltraVNC repeater authenticated out-of-bounds write in rule parser via oversized tokenEPSS 0.9%CVE-2026-7831HIGHUltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsingEPSS 0.7%CVE-2019-25600HIGHUltraVNC Viewer 1.2.2.4 Denial of Service via Buffer OverflowEPSS 0.7%CVE-2026-7839CRITICALUltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin accessEPSS 0.7%CVE-2026-44042LOWUltraVNC repeater wi_uudecode off-by-one in base64 decode boundary checkEPSS 0.5%CVE-2019-25564MEDIUMPCHelpWareV2 1.0.0.5 Denial of Service via Group FieldEPSS 0.4%CVE-2026-44041MEDIUMUltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminatedEPSS 0.4%CVE-2026-44040MEDIUMUltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge bytesEPSS 0.4%CVE-2026-7830HIGHUltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interceptionEPSS 0.3%CVE-2019-25601MEDIUMUltraVNC Launcher 1.2.2.4 Denial of Service Buffer OverflowEPSS 0.3%CVE-2019-25563MEDIUMPCHelpWareV2 1.0.0.5 Denial of Service via SC CreationEPSS 0.2%