3 results (0.001 seconds)

CVSS: 7.8EPSS: 11%CPEs: 1EXPL: 2

06 Feb 2007 — Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a ServerInit packet, which triggers a failed malloc and a resulting NULL dereference. Chicken of the VNC (cotv) 2.0 permite a atacantes remotos provocar una denegación de servicio (cierre de aplicación) mediante un valor de tamaño de nombre muy grande en un paquete ServerInit, lo cual dispara un malloc fallido y la referencia a NULL resultante. • https://www.exploit-db.com/exploits/3257 •

CVSS: 9.8EPSS: 93%CPEs: 1EXPL: 9

15 May 2006 — RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password. RealVNC 4.1.1 y otros productos que usan RealVNC tales como AdderLink IP y Cisco CallManager, permite a atacantes remotos eludir autenticación a través de una petic... • https://packetstorm.news/files/id/180978 • CWE-287: Improper Authentication •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 2

31 Dec 2004 — RealVNC 4.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of connections to port 5900. • http://marc.info/?l=bugtraq&m=109346198700529&w=2 •