Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

fstec логотип

BDU:2026-10983

около 2 месяцев назад

Уязвимость функции http_proxy_connect() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-67289

около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-67289

около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2026-67289

около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-67289

около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x8f-6ffv-v2wc

около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
EPSS: Низкий
rocky логотип

RLSA-2026:54487

18 дней назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:54485

19 дней назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54487

20 дней назад

ELSA-2026-54487: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54485

20 дней назад

ELSA-2026-54485: freerdp security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:54486

19 дней назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54486

20 дней назад

ELSA-2026-54486: freerdp security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-10983

Уязвимость функции http_proxy_connect() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-67289

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-67289

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-67289

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-67289

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate ...

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3x8f-6ffv-v2wc

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:54487

Important: freerdp security update

18 дней назад
rocky логотип
RLSA-2026:54485

Important: freerdp security update

19 дней назад
oracle-oval логотип
ELSA-2026-54487

ELSA-2026-54487: freerdp security update (IMPORTANT)

20 дней назад
oracle-oval логотип
ELSA-2026-54485

ELSA-2026-54485: freerdp security update (IMPORTANT)

20 дней назад
rocky логотип
RLSA-2026:54486

Important: freerdp security update

19 дней назад
oracle-oval логотип
ELSA-2026-54486

ELSA-2026-54486: freerdp security update (IMPORTANT)

20 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.