VendorsAttwinvncall versions
Vulnerabilities

Att Winvnc

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2001-0168
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.
Published 2001-03-09 · Modified
10.01 PoCEPSS 0.707
CVE-2000-1164
WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.
Published 2001-05-07 · Modified
9.0EPSS 0.015
CVE-2001-0167
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.
Published 2001-03-09 · Modified
7.61 PoCEPSS 0.508
CVE-2001-1422
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
Published 2005-03-20 · Modified
7.5EPSS 0.021