Home/Product/apache guacamole
Product

apache guacamole

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-35164
>= 0.8.0 and < 1.6.0
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-
6.8MEDIUM
CVE-2023-43826
<= 1.5.3
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer over
7.5HIGH
CVE-2023-30576
>= 0.9.0 and < 1.5.2
Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allo
6.8MEDIUM
CVE-2023-30575
< 1.5.2
Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol
6.5MEDIUM
CVE-2021-43999
all versions
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is ena
8.8HIGH
CVE-2021-41767
<= 1.3.0
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST respo
6.5MEDIUM
CVE-2020-11997
<= 1.2.0
Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple
4.3MEDIUM
CVE-2020-9498
<= 1.1.0
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a
6.7MEDIUM
CVE-2020-9497
<= 1.1.0
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconn
4.4MEDIUM
CVE-2019-19603
all versions
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
7.5HIGH
CVE-2018-1340
<= 0.9.14
Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure
7.5HIGH
CVE-2017-3158
<= 0.9.9
A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of prin
8.1HIGH
CVE-2016-1566
all versions
Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a loca
5.4MEDIUM
CVE-2012-4415
<= 0.6.2
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers t
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin