Guacamole
Vulnerabilities
2
Known exploited
0
Max CVSS
8.1
Top EPSS
0.021
Severity breakdown
Critical
0
High
2
Medium
0
Low
0
Also matched as (raw): guacamole
Top vulnerabilities
CVE-2017-3158A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resulting in the remaining data being written beyond the end of a statically-allocated buffer.
CVE-2018-1340Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.