PoC Index

CVE-2009-0388

HIGH 10.0EPSS 13.3%

Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
13.33% chance of exploitation in the next 30 days, 96th percentile
Published
2009-02-04
Updated
2024-08-07

ExploitDB entries (2)

References

Related