Unrated severityNVD Advisory· Published Feb 4, 2009· Updated Apr 23, 2026
CVE-2009-0388
CVE-2009-0388
Description
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.coresecurity.com/content/vnc-integer-overflowsnvdExploit
- www.securityfocus.com/bid/33568nvdExploitPatch
- forum.ultravnc.info/viewtopic.phpnvd
- secunia.com/advisories/33807nvd
- vnc-tight.svn.sourceforge.net/viewvc/vnc-tightnvd
- www.securityfocus.com/archive/1/500632/100/0/threadednvd
- www.vupen.com/english/advisories/2009/0321nvd
- www.vupen.com/english/advisories/2009/0322nvd
- www.exploit-db.com/exploits/7990nvd
- www.exploit-db.com/exploits/8024nvd
News mentions
0No linked articles in our index yet.