HIGH8.8CVE-2021-43999Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. >= 1.2.0, <= 1.2.0, >= 1.3.0, <= 1.3.0
HIGH8.8CVE-2023-43826Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. from 0, < 1.5.3
HIGH8.1CVE-2023-30576Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. >= 0.9.0, < 1.5.2
HIGH7.5Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake…
from 0, < 1.5.2
MEDIUM6.7Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels.
from 0, < 1.1.0
MEDIUM6.5Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses.
from 0, < 1.3.0
MEDIUM4.4guacamole-server - security update
from 0, < 1.1.0
MEDIUM4.3Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility.
from 0, < 1.2.0