VDB

CVE-2019-15678

CVE-2019-15678 PUBLISHED

TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

EPSS 2.63% · 86.0th percentile

Risk Scores

EPSS Score
2.63%
86.0th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSdirectvnc0.7.8-1, 0
Ubuntu:20.04:LTSbochs2.6.9+dfsg-3build1, 2.6.9+dfsg-4, 0
Ubuntu:18.04:LTSx2vnc1.7.2-6, 0
Ubuntu:22.04:LTSvncsnapshot1.2a-5.1build2, 0
Ubuntu:22.04:LTSbochs*, 2.7+dfsg-2, 0
Ubuntu:16.04:LTSx2vnc0, 1.7.2-5
Ubuntu:24.04:LTSvncsnapshot0, *
Ubuntu:20.04:LTSvncsnapshot1.2a-5.1build1, 1.2a-5.1build2, 0
Ubuntu:18.04:LTSvncsnapshot*, 0, 1.2a-5.1build1
Ubuntu:20.04:LTSssvnc1.0.29-5, 0, 1.0.29-4build1
Ubuntu:25.10x2vnc1.7.2+git20100909.01ced3d-2, 0, *
Ubuntu:16.04:LTSdirectvnc0, 0.7.7-1
Ubuntu:16.04:LTSssvnc1.0.29-2+deb8u1build0.16.04.1, 0, 1.0.29-2build1
Ubuntu:24.04:LTSveyon4.7.5+repack1-1build2, 4.7.5+repack1-1ubuntu1, 0
Ubuntu:20.04:LTSx2vnc0, 1.7.2-6
Ubuntu:20.04:LTStightvnc0, 1.3.10-0ubuntu5
Ubuntu:24.04:LTStightvnc0, 1:1.3.10-7, 1:1.3.10-7build2
Ubuntu:18.04:LTSssvnc1.0.29-3build1, 0, 1.0.29-3
Ubuntu:25.10tightvnc0, 1:1.3.10-10, 1:1.3.10-9
Ubuntu:20.04:LTSdirectvnc0.7.7-1build1, 0

…and 21 more

Timeline

  • Oct 29, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Mar 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›