CVE-2019-8280

CRITICAL

UltraVNC < 1.2.2.3 - Out-of-bounds Read in RAW Decoder

Title source: llm
STIX 2.1

Description

UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially result code execution. This attack appear to be exploitable via network connectivity. This vulnerability has been fixed in revision 1204.

Scores

CVSS v3 9.8
EPSS 0.0425
EPSS Percentile 89.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-125 CWE-787 CWE-788
Status published
Products (1)
uvnc/ultravnc < 1.2.2.3
Published Mar 08, 2019
Tracked Since Feb 18, 2026