10

CVE-2008-4770

The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RealvncRealvnc Version4.0 Editionfree
RealvncRealvnc Version4.1.2 Editionfree
RealvncRealvnc Version4.4.2 Editionenterprise
RealvncRealvnc Versione4.0 Editionenterprise
RealvncRealvnc Versionp4.0 Editionpersonal
RealvncRealvnc Versionp4.4.2 Editionpersonal
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.82% 0.902
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.