Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-52720

Опубликовано: 15 июн. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

EPSS

Процентиль: 47%
0.00638
Низкий

8.8 High

CVSS3

Дефекты

CWE-122
CWE-122

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

CVSS3: 8.8
redhat
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

CVSS3: 8.8
debian
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb ( ...

CVSS3: 8.8
github
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

EPSS

Процентиль: 47%
0.00638
Низкий

8.8 High

CVSS3

Дефекты

CWE-122
CWE-122