Releases19
Frequency8 months 3 weeks
Last Release
TightVNC is a free remote control software package. With TightVNC, you can see the desktop of a remote machine and control it with your local mouse and keyboard, just like you would do it sitting in the front of that computer. TightVNC is: * free for both personal and commercial usage, with full source code available, * useful in administration, tech support, education, and for many other purposes, * cross-platform, available for Windows and Unix, with Java client included, * compatible with standard VNC software, conforming to RFB protocol specifications. With TightVNC, you can: * cut your expenses and save your time on traveling, * help your friends and family to solve problems with their computers remotely, * make sure nothing wrong is happening on your computers when you are away. [Screenshots](http://www.tightvnc.com/screenshots.php).

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 2.8.759 CRITICAL

TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.

= 1.3.10

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15679. Reason: This candidate is a duplicate of CVE-2019-15679. Notes: All CVE users should reference CVE-2019-15679 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

<= 2.8.599.8 CRITICAL7.5 HIGH

Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instructions via a crafted FramebufferUpdate packet from a VNC server.

= 1.3.109.8 CRITICAL7.5 HIGH

TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.

= 1.3.107.5 HIGH5 MEDIUM

TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.

= 1.3.109.8 CRITICAL7.5 HIGH

TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

= 1.3.109.8 CRITICAL7.5 HIGH

TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.