Unrated severityNVD Advisory· Published Feb 6, 2008· Updated Apr 23, 2026
CVE-2008-0610
CVE-2008-0610
Description
Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a modified size value.
Affected products
5cpe:2.3:a:ultravnc:ultravnc:1.0.2:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:ultravnc:ultravnc:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ultravnc:ultravnc:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:ultravnc:ultravnc:1.0.4_rc6:*:*:*:*:*:*:*
- cpe:2.3:a:ultravnc:ultravnc:1.0.4_rc7:*:*:*:*:*:*:*
- cpe:2.3:a:ultravnc:ultravnc:1.0.4_rc8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/28747nvdPatchVendor Advisory
- www.securityfocus.com/bid/27561nvdExploitPatch
- www.kb.cert.org/vuls/id/721460nvdUS Government Resource
- forum.ultravnc.info/viewtopic.phpnvd
- sourceforge.net/project/shownotes.phpnvd
- ultravnc.svn.sourceforge.net/viewvc/ultravnc/UltraVNC%20Project%20Root/UltraVNC/vncviewer/ClientConnection.cppnvd
- www.exploit-db.com/exploits/18666nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/0392nvd
News mentions
0No linked articles in our index yet.