Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

ubuntu логотип

CVE-2026-22858

7 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access. This vulnerability is fixed in 3.20.1.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-22858

7 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access. This vulnerability is fixed in 3.20.1.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-22858

7 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access. This vulnerability is fixed in 3.20.1.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-22858

7 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2026-00620

больше 1 года назад

Уязвимость RDP-клиента FreeRDP, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20260611-73-0004

около 2 месяцев назад

Уязвимость freerdp3

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20260611-73-0003

около 2 месяцев назад

Уязвимость freerdp

CVSS3: 6.8
EPSS: Низкий
rocky логотип

RLSA-2026:3334

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:3067

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-4471

4 месяца назад

ELSA-2026-4471: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3334

5 месяцев назад

ELSA-2026-3334: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3067

5 месяцев назад

ELSA-2026-3067: freerdp security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:3068

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3068

5 месяцев назад

ELSA-2026-3068: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0345-1

6 месяцев назад

Security update for freerdp

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19033

23 дня назад

ELSA-2026-19033: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20339-1

5 месяцев назад

Security update for freerdp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-22858

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access. This vulnerability is fixed in 3.20.1.

CVSS3: 9.1
1%
Низкий
7 месяцев назад
redhat логотип
CVE-2026-22858

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access. This vulnerability is fixed in 3.20.1.

CVSS3: 7.4
1%
Низкий
7 месяцев назад
nvd логотип
CVE-2026-22858

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access. This vulnerability is fixed in 3.20.1.

CVSS3: 9.1
1%
Низкий
7 месяцев назад
debian логотип
CVE-2026-22858

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.1
1%
Низкий
7 месяцев назад
fstec логотип
BDU:2026-00620

Уязвимость RDP-клиента FreeRDP, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.8
1%
Низкий
больше 1 года назад
redos логотип
ROS-20260611-73-0004

Уязвимость freerdp3

CVSS3: 6.8
1%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260611-73-0003

Уязвимость freerdp

CVSS3: 6.8
1%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:3334

Important: freerdp security update

5 месяцев назад
rocky логотип
RLSA-2026:3067

Important: freerdp security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-4471

ELSA-2026-4471: freerdp security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2026-3334

ELSA-2026-3334: freerdp security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-3067

ELSA-2026-3067: freerdp security update (IMPORTANT)

5 месяцев назад
rocky логотип
RLSA-2026:3068

Important: freerdp security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-3068

ELSA-2026-3068: freerdp security update (IMPORTANT)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0345-1

Security update for freerdp

6 месяцев назад
oracle-oval логотип
ELSA-2026-19033

ELSA-2026-19033: freerdp security update (IMPORTANT)

23 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20339-1

Security update for freerdp

5 месяцев назад

Уязвимостей на страницу