CVE-2019-8275

UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
Configurations

Configuration 1 (hide)

cpe:2.3:a:uvnc:ultravnc:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:siemens:sinumerik_access_mymachine\/p2p:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinumerik_pcu_base_win10_software\/ipc:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinumerik_pcu_base_win7_software\/ipc:*:*:*:*:*:*:*:*

History

11 May 2021, 13:15

Type Values Removed Values Added
References
  • (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-940818.pdf -
  • (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-286838.pdf -

Information

Published : 2019-03-08 23:29

Updated : 2023-12-10 12:59


NVD link : CVE-2019-8275

Mitre link : CVE-2019-8275

CVE.ORG link : CVE-2019-8275


JSON object : View

Products Affected

uvnc

  • ultravnc

siemens

  • sinumerik_pcu_base_win7_software\/ipc
  • sinumerik_pcu_base_win10_software\/ipc
  • sinumerik_access_mymachine\/p2p
CWE
NVD-CWE-Other CWE-170

Improper Null Termination