CVE-2023-43826
published 2023-12-19CVE-2023-43826: Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.89%
55.4th percentile
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process.
Users are recommended to upgrade to version 1.5.4, which fixes this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | guacamole | <= 1.5.3 | — |
| apache | guacamole | — | — |
| apache_software_foundation | apache_guacamole | <= 1.5.3 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_apache7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache guacamole: CVE-2023-43826
vendor_apache·CVSS 7.5
CVE-2023-43826 [HIGH] Apache guacamole: CVE-2023-43826
Apache guacamole: CVE-2023-43826
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process. Acknowledgements: We would like to thank Joseph Surin (Elttam) and Matt Jones (Elttam) for reporting this issue.
GHSA
Liferay Portal Vulnerable to XSS in Web Content translation
ghsa·2025-10-01
CVE-2025-43826 [MEDIUM] CWE-79 Liferay Portal Vulnerable to XSS in Web Content translation
Liferay Portal Vulnerable to XSS in Web Content translation
Stored Cross-site Scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow remote attackers to inject arbitrary web script or HTML via any rich text field in a web content article.
GHSA
GHSA-hhj4-xc5f-6f87: Apache Guacamole 1
ghsa_unreviewed·2023-12-19
CVE-2023-43826 [HIGH] CWE-190 GHSA-hhj4-xc5f-6f87: Apache Guacamole 1
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process.
Users are recommended to upgrade to version 1.5.4, which fixes this issue.
OSV
CVE-2023-43826: Apache Guacamole 1
osv·2023-12-19·CVSS 8.8
CVE-2023-43826 [HIGH] CVE-2023-43826: Apache Guacamole 1
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process. Users are recommended to upgrade to version 1.5.4, which fixes this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-19
Published