Update

TightVNC

GlavSoft LLC.

TightVNC

to version 2.8.85

View all applications

CVE Vulnerabilities for TightVNC

CVEPublishedSeverityDetailsExploitabilityImpact Vector
CVE‑2023‑278302023‑04‑12 15:15:13CRITICAL (9)TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.26NETWORK
CVE‑2021‑427852021‑11‑23 22:15:08CRITICAL (10)Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instructions via a crafted FramebufferUpdate packet from a VNC server.46NETWORK
CVE‑2019‑82872019‑10‑29 19:15:23CRITICAL (10)TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.46NETWORK
CVE‑2019‑156802019‑10‑29 19:15:18HIGH (8)TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.44NETWORK
CVE‑2019‑156792019‑10‑29 19:15:18CRITICAL (10)TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.46NETWORK
CVE‑2019‑156782019‑10‑29 19:15:18CRITICAL (10)TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.46NETWORK

View OS-specific patching for:
Windows Mac Linux
Logos, products, trade names, and company names are all the property of their respective trademark holders.
The above listing includes products that Lavawall® monitors through public information and/or proprietary statistical analysis.
Although we do have a partner relationship with some of the listed products and companies, they do not necessarily endorse Lavawall® or have integrations with our systems.