← Vulnerability feed

Vulnerability record · CVE-2019-15678 · published 29 October 2019

CVE-2019-15678: Tightvnc heap-based buffer overflow vulnerability

Tightvnc · Tightvnc

TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

9.8 CVSS 3.1 Critical EPSS 12% · top 4.0% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 7.5
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15678 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0388Tightvnc vulnerabilityMultiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap…EPSS 13%9.8CVE-2021-42785Tightvnc classic buffer overflow vulnerabilityBuffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instructions via a crafted Framebuffe…EPSS 2.3%9.8CVE-2019-8287Tightvnc classic buffer overflow vulnerabilityTightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This atta…EPSS 19%9.8CVE-2019-15679Tightvnc heap-based buffer overflow vulnerabilityTightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This att…EPSS 12%9.0CVE-2023-27830Tightvnc improper privilege management vulnerabilityTightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when e…EPSS 1.1%7.5CVE-2019-15680Tightvnc null pointer dereference vulnerabilityTightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to…EPSS 2.7%7.5CVE-2002-1336Tightvnc vulnerabilityTightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sni…EPSS 2.4%5.0CVE-2002-1511Att vnc vulnerabilityThe vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2019-15678), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.