CVE-2019-8275

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/03/2019
Last modified:
28/06/2021

Description

UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uvnc:ultravnc:*:*:*:*:*:*:*:* 1.2.2.3 (excluding)
cpe:2.3:a:siemens:sinumerik_access_mymachine\/p2p:*:*:*:*:*:*:*:* 4.8 (excluding)
cpe:2.3:a:siemens:sinumerik_pcu_base_win10_software\/ipc:*:*:*:*:*:*:*:* 14.00 (excluding)
cpe:2.3:a:siemens:sinumerik_pcu_base_win7_software\/ipc:*:*:*:*:*:*:*:* 12.01 (including)