Deskflow

Deskflow

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 17.08.2026 21:00:41
  • Zuletzt bearbeitet 18.08.2026 18:19:22

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp, causing the server path in s...

  • EPSS 0.31%
  • Veröffentlicht 17.08.2026 20:59:08
  • Zuletzt bearbeitet 18.08.2026 16:18:13

Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value follo...

  • EPSS 0.26%
  • Veröffentlicht 17.08.2026 20:57:19
  • Zuletzt bearbeitet 18.08.2026 16:18:12

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value afte...

  • EPSS 0.28%
  • Veröffentlicht 12.05.2026 20:52:59
  • Zuletzt bearbeitet 13.05.2026 16:10:57

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). When any TCP peer connects to the listening port and i...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 24.04.2026 19:50:21
  • Zuletzt bearbeitet 28.04.2026 15:46:28

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with WorldAccessOption enabled. The daemon processes privileged commands without authentication, allowing ...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 24.04.2026 19:47:45
  • Zuletzt bearbeitet 28.04.2026 15:47:41

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's clipboard deserialization allows a connected peer to trigger an out-of-bounds read by sending a malformed clipboard update. The iss...