tightvnc kayıtları
tightvnc üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %41,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-122 Heap-based Buffer Overflow2
- CWE-189 Numeric Errors1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-269 Improper Privilege Management1
- CWE-476 NULL Pointer Dereference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2019-8287İstismar yok | TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution.tightvnc · tightvnc · CWE-120 | Kritik9,8 | — | %19,5 | 29 Eki 2019 |
44Planlayın | CVE-2009-0388Kavram kanıtı | Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of servtightvnc · tightvnc · CWE-189 | Kritik10,0 | — | %13,3 | 4 Şub 2009 |
43Planlayın | CVE-2019-15678İstismar yok | TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution..tightvnc · tightvnc · CWE-122 | Kritik9,8 | — | %12,2 | 29 Eki 2019 |
43Planlayın | CVE-2019-15679İstismar yok | TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution.tightvnc · tightvnc · CWE-122 | Kritik9,8 | — | %11,8 | 29 Eki 2019 |
40Planlayın | CVE-2021-42785İstismar yok | Buffer Overflow in tvnviewer.exe via Crafted Packet in TightVNC Viewer 2.8.59tightvnc · tightvnc · CWE-120 | Kritik9,8 | — | %2,3 | 23 Kas 2021 |
37İzleyin | CVE-2024-42049Kavram kanıtı | TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.CWE-200 | Kritik9,1 | — | %2,1 | 27 Tem 2024 |
36İzleyin | CVE-2023-27830İstismar yok | TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted filtightvnc · tightvnc · CWE-269 | Kritik9,0 | — | %1,1 | 12 Nis 2023 |
31İzleyin | CVE-2019-15680İstismar yok | TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS).tightvnc · tightvnc · CWE-476 | Yüksek7,5 | — | %2,7 | 29 Eki 2019 |
31İzleyin | CVE-2002-1336İstismar yok | TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authenticatitightvnc · tightvnc | Yüksek7,5 | — | %2,4 | 11 Ara 2002 |
21İzleyin | CVE-2002-1511İstismar yok | The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookiesatt · vnc | Orta5,0 | — | %1,8 | 3 Mar 2003 |
18İzleyin | CVE-2002-0971İstismar yok | Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging Systetightvnc · tightvnc | Orta4,6 | — | %0,4 | 24 Eyl 2002 |
8İzleyin | CVE-2002-1848İstismar yok | TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which cotightvnc · tightvnc | Düşük2,1 | — | %0,3 | 31 Ara 2002 |
- CVE-2019-828745Planlayın
TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution.
KritikCVSS 9,8İstismar yokEPSS %19tightvnc · tightvnc29 Eki 2019
- CVE-2009-038844Planlayın
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of serv
KritikCVSS 10,0Kavram kanıtıEPSS %13tightvnc · tightvnc4 Şub 2009
- CVE-2019-1567843Planlayın
TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution..
KritikCVSS 9,8İstismar yokEPSS %12tightvnc · tightvnc29 Eki 2019
- CVE-2019-1567943Planlayın
TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution.
KritikCVSS 9,8İstismar yokEPSS %12tightvnc · tightvnc29 Eki 2019
- CVE-2021-4278540Planlayın
Buffer Overflow in tvnviewer.exe via Crafted Packet in TightVNC Viewer 2.8.59
KritikCVSS 9,8İstismar yokEPSS %2tightvnc · tightvnc23 Kas 2021
- CVE-2024-4204937İzleyin
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
KritikCVSS 9,1Kavram kanıtıEPSS %227 Tem 2024
- CVE-2023-2783036İzleyin
TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted fil
KritikCVSS 9,0İstismar yokEPSS %1tightvnc · tightvnc12 Nis 2023
- CVE-2019-1568031İzleyin
TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS).
YüksekCVSS 7,5İstismar yokEPSS %3tightvnc · tightvnc29 Eki 2019
- CVE-2002-133631İzleyin
TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authenticati
YüksekCVSS 7,5İstismar yokEPSS %2tightvnc · tightvnc11 Ara 2002
- CVE-2002-151121İzleyin
The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies
OrtaCVSS 5,0İstismar yokEPSS %2att · vnc3 Mar 2003
- CVE-2002-097118İzleyin
Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging Syste
OrtaCVSS 4,6İstismar yokEPSS %0tightvnc · tightvnc24 Eyl 2002
- CVE-2002-18488İzleyin
TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which co
DüşükCVSS 2,1İstismar yokEPSS %0tightvnc · tightvnc31 Ara 2002