← Back

Cybelsoft

cybelsoft

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Thinvnc
thinvnc

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cybelsoft
1Thinvnc
Jun 17, 2026
Apr 18, 2022
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve...Show more
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.Show less
1Cybelsoft
1Thinvnc
Jun 17, 2026
Oct 16, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for...Show more
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.Show less