Vulnerability Description
TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tightvnc | Tightvnc | 1.2 |
References
- http://www.securityfocus.com/bid/4835
- http://www.tightvnc.com/changelog-win32.html
- http://www.securityfocus.com/bid/4835
- http://www.tightvnc.com/changelog-win32.html
FAQ
What is CVE-2002-1848?
CVE-2002-1848 is a vulnerability with a CVSS score of 2.1 (LOW). TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.
How severe is CVE-2002-1848?
CVE-2002-1848 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1848?
Check the references section above for vendor advisories and patch information. Affected products include: Tightvnc Tightvnc.