CVE-2019-8258

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
05/03/2019
Last modified:
19/10/2020

Description

UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uvnc:ultravnc:*:*:*:*:*:*:*:* 1.2.2.3 (excluding)
cpe:2.3:a:siemens:sinumerik_access_mymachine\/p2p:*:*:*:*:*:*:*:* 4.8 (excluding)
cpe:2.3:a:siemens:sinumerik_pcu_base_win10_software\/ipc:*:*:*:*:*:*:*:* 14.00 (excluding)
cpe:2.3:a:siemens:sinumerik_pcu_base_win7_software\/ipc:*:*:*:*:*:*:*:* 12.01 (including)