-Infinity
0

Vendor Risk Score

See how uvnc compares to other vendors in security performance

View Risk Score →

UltraVNC UltraVNC RepeaterUltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)

Risk 86
Severity
9.3
First published (updated )

UltraVNC UltraVNC RepeaterUltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access

Risk 66
Severity
9.1
First published (updated )

UltraVNC UltraVNC ViewerUltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length

Risk 77
Severity
8.7
First published (updated )

UltraVNC viewerUltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing

Risk 57
Severity
7.6
First published (updated )

UltraVNCUltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception

Risk 56
Severity
7.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

UltraVNC UltraVNC RepeaterUltraVNC repeater authenticated out-of-bounds write in rule parser via oversized token

Risk 66
Severity
7.2
First published (updated )

UltraVNC UltraVNC RepeaterUltraVNC repeater integer overflow in win_log malloc leading to heap overflow

Risk 27
Severity
5.3
First published (updated )

UltraVNC UltraVNCUltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge bytes

Risk 40
Severity
6.5
First published (updated )

UltraVNC UltraVNCUltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated

Risk 40
Severity
6.5
First published (updated )

UltraVNC RepeaterUltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check

Risk 20
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

UltraVNC UltraVNCUltraVNC Service version.dll uncontrolled search path

Risk 49
Severity
6.4
EPSS
0.01%
First published (updated )

PCHelpWareV2PCHelpWareV2 1.0.0.5 Denial of Service via Group Field

Risk 36
Severity
6.8
First published (updated )

PCHelpWareV2 PCHelpWareV2PCHelpWareV2 1.0.0.5 Denial of Service via SC Creation

Risk 38
Severity
6.9
First published (updated )

UltraVNC UltraVNCUltraVNC Windows Service cryptbase.dll uncontrolled search path

Risk 49
Severity
7.3
EPSS
0.01%
First published (updated )

UltraVNC UltraVNC LauncherUltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

UltraVNC UltraVNC LauncherUltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service

Risk 37
Severity
6.7
First published (updated )

Uvnc UltravncLow privilege user is able to exploit the service and gain SYSTEM privileges in UltraVNC server

Risk 72
Severity
8.8
First published (updated )

Uvnc UltravncUltraVNC revision 1211 contains multiple memory leaks (CWE-665) in VNC server code, which allows an …

Risk 45
Severity
7.5
First published (updated )

Uvnc UltravncUltraVNC revision 1198 contains multiple memory leaks (CWE-655) in VNC client code, which allow an a…

Risk 45
Severity
7.5
First published (updated )

Uvnc UltravncUltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused…

Risk 88
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Uvnc UltravncBuffer Overflow

Risk 38
Severity
6.5
First published (updated )

Uvnc UltravncUltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decode…

Risk 88
Severity
9.8
First published (updated )

Uvnc UltravncUltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentiall…

Risk 86
Severity
9.8
First published (updated )

Uvnc UltravncBuffer Overflow

Risk 88
Severity
9.8
First published (updated )

Uvnc UltravncBuffer Overflow

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Uvnc UltravncUltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, w…

Risk 88
Severity
9.8
First published (updated )

Uvnc UltravncBuffer Overflow

Risk 86
Severity
9.8
First published (updated )

Uvnc UltravncUltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, whic…

Risk 88
Severity
9.8
First published (updated )

Uvnc UltravncUltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, wh…

Risk 88
Severity
9.8
First published (updated )

Uvnc UltravncUltraVNC revision 1207 has out-of-bounds read vulnerability in VNC client code inside TextChat modul…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203