PoC Index

CVE-2006-1652

HIGH 9.0EPSS 67.4%

Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malicious server that sends a long string to a client that connects on TCP port 5900, which triggers an overflow in Log::ReallyPrint; and (2) allow remote attackers to cause a denial of service (server crash) via a long HTTP GET request to TCP port 5800, which triggers an overflow in VNCLog::ReallyPrint.

CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
67.40% chance of exploitation in the next 30 days, 99th percentile
Published
2006-04-06
Updated
2024-08-07

Proof-of-concept exploits (3)

Metasploit modules (1)

ExploitDB entries (3)

References

Related