← All credits
Arjun Basnet, Securin (arjun.basnet@securin.io)
10 vulnerability records and advisories credit this contributor.
CVE-2026-7840
UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)
CVE-2026-7839
UltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access
CVE-2026-7838
UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length
CVE-2026-7831
UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
CVE-2026-7830
UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception
CVE-2026-7829
UltraVNC repeater authenticated out-of-bounds write in rule parser via oversized token
CVE-2026-7828
UltraVNC repeater integer overflow in win_log malloc leading to heap overflow
CVE-2026-44042
UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check
CVE-2026-44041
UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated
CVE-2026-44040
UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge bytes