I would say that any open port is a hazard, as you don't know if the naughty people will try and use these ports to get access as they will sniff out any open port to "attack".
Can't remember if ZA allows it or not, but can you tell it to only allow these ports to be accessed by ultraVNC only so anything else trying to use these ports gets blocked?