Vulnerabilities > Apache > Guacamole > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-19 CVE-2023-43826 Unspecified vulnerability in Apache Guacamole
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow.
network
low complexity
apache
8.8
2023-06-07 CVE-2023-30575 Unspecified vulnerability in Apache Guacamole
Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through specially-crafted data.
network
low complexity
apache
7.5
2023-06-07 CVE-2023-30576 Unspecified vulnerability in Apache Guacamole
Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer.
network
high complexity
apache
8.1
2022-01-11 CVE-2021-43999 Improper Authentication vulnerability in Apache Guacamole 1.2.0/1.3.0
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider.
network
low complexity
apache CWE-287
8.8
2019-12-09 CVE-2019-19603 SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
network
low complexity
sqlite oracle siemens apache netapp
7.5
2019-02-07 CVE-2018-1340 Missing Encryption of Sensitive Data vulnerability in Apache Guacamole
Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token.
network
low complexity
apache CWE-311
7.5
2018-01-18 CVE-2017-3158 Race Condition vulnerability in Apache Guacamole
A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap.
network
high complexity
apache CWE-362
8.1